CVEs Blog | G5 Cyber Security

CVE-2015-2296 – The resolve_redirects function in sessions.py in requests 2.1.0 through 2

The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2296

Reference (s):

Exit mobile version