CVE-2015-2296
Publication date 16 March 2015
Last updated 24 July 2024
Ubuntu priority
The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
Status
Package | Ubuntu Release | Status |
---|---|---|
requests | ||
14.04 LTS trusty |
Fixed 2.2.1-1ubuntu0.2
|
|
Notes
References
Related Ubuntu Security Notices (USN)
- USN-2531-1
- Requests vulnerability
- 16 March 2015