Back to Database
Status published
Medium
CVE-2015-2296
The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3...
Vulnerability Description
The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-2296
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.openwall.com/lists/oss-security/2015/03/15/1
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153594.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:133
- http://www.openwall.com/lists/oss-security/2015/03/14/4
- http://www.ubuntu.com/usn/USN-2531-1
- https://github.com/kennethreitz/requests/commit/3bd8afbff29e50b38f889b2f688785a669b9aafc
- http://advisories.mageia.org/MGASA-2015-0120.html
- https://warehouse.python.org/project/requests/2.6.0/
More from mageia project
View All →CVE-2014-9037
WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and...
Medium
6.8
CVE-2014-8764
DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP...
Medium
5
CVE-2014-3424
lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users...
Low
3.3
CVE-2014-3423
lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users...
Low
3.3
CVE-2014-3421
lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users...
Low
3.3
Affected Vendor
mageia project
View all reports →Affected Software
mageia, requests, ubuntu linux
Vulnerable Versions:
4.0, 2.1.0, 2.2.1, 2.3.0, 2.4.0, 2.4.1, 2.4.2, 2.4.3, 2.5.0, 2.5.1, 2.5.2, 2.5.3, 14.04, 14.10
Timeline
Official Publish:
March 18th, 2015
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.