The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2015-03-18 09:59
Updated : 2021-03-18 06:19
NVD link : CVE-2015-2296
Mitre link : CVE-2015-2296
JSON object : View
CWE
Products Affected
mageia_project
- mageia
canonical
- ubuntu_linux
python
- requests