Insufficiently Protected Credentials in Requests
High severity
GitHub Reviewed
Published
Oct 29, 2018
to the GitHub Advisory Database
•
Updated Oct 21, 2024
Description
Published by the National Vulnerability Database
Oct 9, 2018
Published to the GitHub Advisory Database
Oct 29, 2018
Reviewed
Jun 16, 2020
Last updated
Oct 21, 2024
The Requests package through 2.19.1 before 2018-09-14 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.
References