Debian 10263 Published by

A requests security update has been released for Debian GNU/Linux 8 and 9 Extended LTS to address an issue that allowing a malicious actor to potentially ex filtrate sensitive information.



ELA-870-1 requests security update

Package : requests
Version : 2.4.3-6+deb8u1 (jessie), 2.12.4-1+deb9u1 (stretch)

Related CVEs :
CVE-2023-32681

Requests, a Python HTTP library, has been leaking Proxy-Authorization headers
to destination servers when redirected to an HTTPS endpoint. For HTTP
connections sent through the tunnel, the proxy will identify the header in the
request itself and remove it prior to forwarding to the destination server.
However when sent over HTTPS, the Proxy-Authorization header must be sent in
the CONNECT request as the proxy has no visibility into the tunneled request.
This results in Requests forwarding proxy credentials to the destination
server unintentionally, allowing a malicious actor to potentially exfiltrate
sensitive information.

ELA-870-1 requests security update