CVE-2015-2296
published 2015-03-18CVE-2015-2296: The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without…
PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.41%
87.5th percentile
The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | requests | < requests 2.4.3-6 (bookworm) | requests 2.4.3-6 (bookworm) |
| mageia_project | mageia | — | — |
| python | requests | — | — |
| python | requests | — | — |
| python | requests | — | — |
| python | requests | — | — |
| python | requests | — | — |
| python | requests | — | — |
| python | requests | — | — |
| python | requests | — | — |
| python | requests | — | — |
| python | requests | — | — |
| python | requests | — | — |
| python | requests | >= 0 < 2.4.3-6 | 2.4.3-6 |
| python | requests | >= 0 < 2.4.3-6 | 2.4.3-6 |
| python | requests | >= 0 < 2.4.3-6 | 2.4.3-6 |
| python | requests | >= 0 < 2.4.3-6 | 2.4.3-6 |
| python | requests | >= 2.1.0 < 2.6.0 | 2.6.0 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Requests vulnerability
vendor_ubuntu·2015-03-16
CVE-2015-2296 Requests vulnerability
Title: Requests vulnerability
Summary: Requests could be made to expose cookies over the network.
Matthew Daley discovered that Requests incorrectly handled cookies without
host values when being redirected. A remote attacker could possibly use
this issue to perform session fixation or cookie stealing attacks.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-requests: session fixation and cookie stealing vulnerability
vendor_redhat·2015-03-14·CVSS 6.8
CVE-2015-2296 [MEDIUM] CWE-201 python-requests: session fixation and cookie stealing vulnerability
python-requests: session fixation and cookie stealing vulnerability
The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
A flaw was found in the way python-requests set the domain cookie parameter for certain HTTP responses. A remote attacker could use this flaw to modify a cookie to be sent to an arbitrary URL.
Package: python-requests (Red Hat Ceph Storage 1.2) - Not affected
Package: python-requests (Red Hat Ceph Storage 1.3) - Not affected
Package: python-requests (Red Hat Enterprise Linux 7) - Not affected
Package: python-requests (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Not affected
Package: python-requests (Red Hat Enterpris
Debian
CVE-2015-2296: requests - The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 al...
vendor_debian·2015·CVSS 6.8
CVE-2015-2296 [MEDIUM] CVE-2015-2296: requests - The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 al...
The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
Scope: local
bookworm: resolved (fixed in 2.4.3-6)
bullseye: resolved (fixed in 2.4.3-6)
forky: resolved (fixed in 2.4.3-6)
sid: resolved (fixed in 2.4.3-6)
trixie: resolved (fixed in 2.4.3-6)
GHSA
Python Requests Session Fixation
ghsa·2022-05-13
CVE-2015-2296 [MEDIUM] Python Requests Session Fixation
Python Requests Session Fixation
The `resolve_redirects` function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
OSV
Python Requests Session Fixation
osv·2022-05-13
CVE-2015-2296 [MEDIUM] Python Requests Session Fixation
Python Requests Session Fixation
The `resolve_redirects` function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
OSV
CVE-2015-2296: The resolve_redirects function in sessions
osv·2015-03-18·CVSS 6.8
CVE-2015-2296 [MEDIUM] CVE-2015-2296: The resolve_redirects function in sessions
The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-2296 python-virtualenv: python-requests: session fixation and cookie stealing vulnerability [epel-6]
bugzilla·2019-11-29·CVSS 6.8
CVE-2015-2296 [MEDIUM] CVE-2015-2296 python-virtualenv: python-requests: session fixation and cookie stealing vulnerability [epel-6]
CVE-2015-2296 python-virtualenv: python-requests: session fixation and cookie stealing vulnerability [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the fol
Bugzilla
CVE-2015-1820 rubygem-rest-client: session fixation vulnerability Set-Cookie headers present in an HTTP 30x redirection responses
bugzilla·2015-03-24·CVSS 9.8
CVE-2015-1820 [CRITICAL] CVE-2015-1820 rubygem-rest-client: session fixation vulnerability Set-Cookie headers present in an HTTP 30x redirection responses
CVE-2015-1820 rubygem-rest-client: session fixation vulnerability Set-Cookie headers present in an HTTP 30x redirection responses
The rest-client team discovered a vulnerability which
has now been fixed in rest-client 1.8.0.
https://rubygems.org/gems/rest-client/versions/1.8.0
https://github.com/rest-client/rest-client/issues/369
The problematic behavior was introduced in rest-client 1.6.1: any
Set-Cookie headers present in an HTTP 30x redirection response are
blindly sent to the redirection target, regardless of domain, path,
expiration, or secure cookie settings. All subsequent 1.6.x and 1.7.x
releases are affected.
Similarly to the issue with python-requests (CVE-2015-2296), the issue could be
exploited in the following ways:
- If you are the redirection source (i.e. you can make re
Bugzilla
CVE-2015-2296 python-requests: session fixation and cookie stealing vulnerability [fedora-21]
bugzilla·2015-03-17·CVSS 6.8
CVE-2015-2296 [MEDIUM] CVE-2015-2296 python-requests: session fixation and cookie stealing vulnerability [fedora-21]
CVE-2015-2296 python-requests: session fixation and cookie stealing vulnerability [fedora-21]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
fedora-21 tracking bug for python-reques
Bugzilla
CVE-2015-2296 python-requests: session fixation and cookie stealing vulnerability
bugzilla·2015-03-17·CVSS 6.8
CVE-2015-2296 [MEDIUM] CVE-2015-2296 python-requests: session fixation and cookie stealing vulnerability
CVE-2015-2296 python-requests: session fixation and cookie stealing vulnerability
The following flaw was found in python-requests:
The issue occurs when Requests is handling a HTTP response that is a redirection and that also sets cookies without an explicit domain parameter. Instead of the cookies only being set for the domain which sent the HTTP response, they are also sent to the redirection target, regardless of its domain.
The issue could be exploited in the following ways:
* If you are the redirection source (ie. you can make Requests hit your URL), you can make Requests perform a request to any third-party domain with cookies of your choosing. This may be useful in performing a session fixation attack.
* If you are the redirection target (ie. you can make a third-party site red
http://advisories.mageia.org/MGASA-2015-0120.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/153594.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2015:133http://www.openwall.com/lists/oss-security/2015/03/14/4http://www.openwall.com/lists/oss-security/2015/03/15/1http://www.ubuntu.com/usn/USN-2531-1https://github.com/kennethreitz/requests/commit/3bd8afbff29e50b38f889b2f688785a669b9aafchttps://warehouse.python.org/project/requests/2.6.0/http://advisories.mageia.org/MGASA-2015-0120.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/153594.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2015:133http://www.openwall.com/lists/oss-security/2015/03/14/4http://www.openwall.com/lists/oss-security/2015/03/15/1http://www.ubuntu.com/usn/USN-2531-1https://github.com/kennethreitz/requests/commit/3bd8afbff29e50b38f889b2f688785a669b9aafchttps://warehouse.python.org/project/requests/2.6.0/
2015-03-18
Published