Yelp / nerve-tools

Tools for configuring SmartStack's Nerve based on local sources
Apache License 2.0
3 stars 12 forks source link

Upgrade requests to version 2.20.0 or later (CVE-2018-18074) #50

Closed nhandler closed 4 years ago

nhandler commented 5 years ago

GitHub flagged the following security vulnerability affecting this repository.

https://nvd.nist.gov/vuln/detail/CVE-2018-18074

CVE-2018-18074 moderate severity Vulnerable versions: <= 2.19.1 Patched version: 2.20.0 The Requests package through 2.19.1 before 2018-09-14 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.

analogue commented 4 years ago

This is fixed: https://github.com/Yelp/nerve-tools/blob/6f4d87c9a196a90751d4348996404e4658c8df3f/src/requirements.txt#L6