Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2018-18074
Description:The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.
Test IDs: 1.3.6.1.4.1.25623.1.0.875269   1.3.6.1.4.1.25623.1.0.843797   1.3.6.1.4.1.25623.1.1.2.2019.1947   1.3.6.1.4.1.25623.1.0.876064   1.3.6.1.4.1.25623.1.0.852922   1.3.6.1.4.1.25623.1.1.2.2019.1886   1.3.6.1.4.1.25623.1.0.843769   1.3.6.1.4.1.25623.1.1.2.2020.1753   1.3.6.1.4.1.25623.1.1.2.2020.1429   1.3.6.1.4.1.25623.1.1.2.2020.1043   1.3.6.1.4.1.25623.1.1.4.2022.1819.1   1.3.6.1.4.1.25623.1.0.875246   1.3.6.1.4.1.25623.1.1.10.2018.0475   1.3.6.1.4.1.25623.1.1.4.2020.0555.1   1.3.6.1.4.1.25623.1.1.2.2020.2201   1.3.6.1.4.1.25623.1.1.2.2020.1633   1.3.6.1.4.1.25623.1.1.4.2019.1487.1   1.3.6.1.4.1.25623.1.1.2.2020.1027   1.3.6.1.4.1.25623.1.1.4.2022.1448.1  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2018-18074
http://docs.python-requests.org/en/master/community/updates/#release-and-version-history
https://bugs.debian.org/910766
https://bugs.debian.org/910766
https://github.com/requests/requests/commit/c45d7c49ea75133e52ab22a8e9e13173938e36ff
https://github.com/requests/requests/commit/c45d7c49ea75133e52ab22a8e9e13173938e36ff
https://github.com/requests/requests/issues/4716
https://github.com/requests/requests/issues/4716
https://github.com/requests/requests/pull/4718
https://github.com/requests/requests/pull/4718
https://www.oracle.com/security-alerts/cpujul2022.html
https://www.oracle.com/security-alerts/cpujul2022.html
RedHat Security Advisories: RHSA-2019:2035
https://access.redhat.com/errata/RHSA-2019:2035
SuSE Security Announcement: openSUSE-SU-2019:1754 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00024.html
https://usn.ubuntu.com/3790-1/
https://usn.ubuntu.com/3790-2/




© 1998-2025 E-Soft Inc. All rights reserved.