CVE-2018-18074: python-requests package may reveal credentials

Bug #1801798 reported by Ken Young
266
This bug affects 1 person
Affects Status Importance Assigned to Milestone
StarlingX
Fix Released
Low
Ghada Khalil

Bug Description

Title
-----
CVE-2018-18074: requests package may reveal credentials

Brief Description
-----------------
The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.

This potential issue was identified by spec file requirement scanning in git hub. The email from GitHub is attached.

Red Hat's analysis is here: https://access.redhat.com/security/cve/cve-2018-18074

NIST is here: https://nvd.nist.gov/vuln/detail/CVE-2018-18074
    - no data yet.

Severity
--------
<Minor: System/Feature is usable with minor issue>

CVE References

Revision history for this message
Ken Young (kenyis) wrote :

Red Hat's analysis of this issue shows that it is criticality is low:

CVSS3 Base Score 2.6
CVSS3 Base Metrics CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

Revision history for this message
Ken Young (kenyis) wrote :
Ken Young (kenyis)
tags: added: stx.security
Revision history for this message
Ken Young (kenyis) wrote :

Reviewed at the security meeting on Nov 19th. The plan is to fix this CVE as part of normal rebasing.

Changed in starlingx:
status: New → Triaged
importance: Undecided → Low
Ken Young (kenyis)
Changed in starlingx:
assignee: nobody → Ken Young (kenyis)
Ghada Khalil (gkhalil)
summary: - CVE-2018-18074: requests package may reveal credentials
+ CVE-2018-18074: python-requests package may reveal credentials
Ghada Khalil (gkhalil)
Changed in starlingx:
assignee: Ken Young (kenyis) → Ghada Khalil (gkhalil)
Ghada Khalil (gkhalil)
information type: Private Security → Public Security
Revision history for this message
Ramaswamy Subramanian (rsubrama) wrote :

Stx 8.0 Debian version has 2.25 version. This issue is already fixed.

Ghada Khalil (gkhalil)
tags: added: stx.8.0
Changed in starlingx:
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.