cbcvebase.
CVE-2023-32681
published 2023-05-26

CVE-2023-32681: Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS…

PriorityP433medium6.1CVSS 3.1
AVNACHPRNUIRSCCHINAN
EPSS
2.97%
85.7th percentile
Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a product of how we use `rebuild_proxies` to reattach the `Proxy-Authorization` header to requests. For HTTP connections sent through the tunnel, the proxy will identify the header in the request itself and remove it prior to forwarding to the destination server. However when sent over HTTPS, the `Proxy-Authorization` header must be sent in the CONNECT request as the proxy has no visibility into the tunneled request. This results in Requests forwarding proxy credentials to the destination server unintentionally, allowing a malicious actor to potentially exfiltrate sensitive information. This issue has been patched in version 2.31.0.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianrequests< requests 2.31.0+dfsg-1 (forky)requests 2.31.0+dfsg-1 (forky)
fedoraprojectfedora
msrccbl2_python-requests_2.27.1-6_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_python-requests_2.22.0-3_on_cbl_mariner_1.0
psfrequests
pythonrequests>= 0 < 2.31.0+dfsg-12.31.0+dfsg-1
pythonrequests>= 0 < 2.31.0+dfsg-12.31.0+dfsg-1
pythonrequests>= 0 < 2.25.1+dfsg-2ubuntu0.32.25.1+dfsg-2ubuntu0.3
pythonrequests>= 0 < 2.31.0+dfsg-1ubuntu1.12.31.0+dfsg-1ubuntu1.1
pythonrequests>= 0 < 2.2.1-1ubuntu0.4+esm12.2.1-1ubuntu0.4+esm1
pythonrequests>= 0 < 2.9.1-3ubuntu0.1+esm22.9.1-3ubuntu0.1+esm2
pythonrequests>= 0 < 2.18.4-2ubuntu0.1+esm22.18.4-2ubuntu0.1+esm2
pythonrequests>= 0 < 2.22.0-2ubuntu1.1+esm12.22.0-2ubuntu1.1+esm1
pythonrequests>= 2.3.0 < 2.31.02.31.0
pythonrequests>= 2.3.0 < 2.31.02.31.0

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_msrc6.1MEDIUM
vendor_redhat6.1MEDIUM
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.