• CVE-2024-47081

发布时间: 2025年6月27日

修改时间: 2025年9月5日

概要

Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.

CVSS v3 指标

NVD openEuler
Confidentiality High
Attack Vector Network
CVSS评分 N/A 5.3
Attack Complexity High
Privileges Required None
Scope Unchanged
Integrity None
User Interaction Required
Availability None

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2688 resource-agents security update 2025年8月9日

影响产品

产品 状态
KY3.4-5 python-requests Fixed
V6 python-requests Fixed
KY3.5.3 python-requests Fixed
KY3.5.2 python-requests Fixed