SUSE-SU-2015:2156-1
Dashboard / Vulnerabilities / SUSE-SU-2015:2156-1
SUSE-SU-2015:2156-1
Summary: Security update for python-requests
Details: python-requests was updated to fix one security issue. This security issue was fixed: - CVE-2015-2296: The resolve_redirects function in sessions.py allowed remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect. (bsc#922448) This non-security issue was fixed: - Don't use the hardcoded path for certificates. (bsc#935252)
References: https://www.suse.com/support/update/announcement/2015/suse-su-20152156-1/, https://bugzilla.suse.com/922448, https://bugzilla.suse.com/935252, https://www.suse.com/security/cve/CVE-2015-2296
Affected packages
Package
Name: python-requests
Purl: pkg:rpm/suse/python-requests&distro=SUSE%20OpenStack%20Cloud%205
Affected ranges
Type: ECOSYSTEM
Events:
