HIGH 7.5 PyPI

Insufficiently Protected Credentials in Requests

GHSA-x84v-xcm2-53pg · CVE-2018-18074 · PYSEC-2018-28

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The Requests package through 2.19.1 before 2018-09-14 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.

Ready to move

Start Securing

Free, no credit card | First findings in minutes