6.8

CVE-2015-2296

The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.

Data is provided by the National Vulnerability Database (NVD)
Mageia ProjectMageia Version4.0
PythonRequests Version2.1.0
PythonRequests Version2.2.1
PythonRequests Version2.3.0
PythonRequests Version2.4.0
PythonRequests Version2.4.1
PythonRequests Version2.4.2
PythonRequests Version2.4.3
PythonRequests Version2.5.0
PythonRequests Version2.5.1
PythonRequests Version2.5.2
PythonRequests Version2.5.3
CanonicalUbuntu Linux Version14.04 SwEditionlts
CanonicalUbuntu Linux Version14.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.82% 0.732
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P