CVE-2018-18074

CVE-2018-18074

The Requests package through 2.19.1 before 2018-09-14 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.

Source: CVE-2018-18074

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다