VDB
Sign up
—

PYSEC-2015-17

Quick fix

PYSEC-2015-17 — requests: upgrade to the fixed version with the command below.

pip install --upgrade 'requests>=3bd8afbff29e50b38f889b2f688785a669b9aafc'

Details

The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/requests
Introduced in: 0Fixed in: 3bd8afbff29e50b38f889b2f688785a669b9aafc
Fixpip install --upgrade 'requests>=3bd8afbff29e50b38f889b2f688785a669b9aafc'

References