CVE-2014-1830

medium
Published 2022-05-14 · Modified 2023-11-08
CVSS v3
CVSS v2
5.0
VIR risk
5.0

Description

Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected request.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-1830

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=733108

OS impact

OSVersionStatusFixed in
suse suse13.1affected
debian debianbookwormfixed2.3.0-1
debian debianbullseyefixed2.3.0-1
debian debianforkyfixed2.3.0-1
debian debiansidfixed2.3.0-1
debian debiantrixiefixed2.3.0-1

Package impact

EcosystemPackageVulnerableFixed
python PyPIrequests<2.3.02.3.0

Application impact

VendorProductVersionsFixed
python pythonrequests{"endIncluding":"2.2.1"}

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.