python-requests-2.25.1-10.el9_6

エラータID: AXSA:2025-10695:03

Release date: 
Tuesday, August 5, 2025 - 14:42
Subject: 
python-requests-2.25.1-10.el9_6
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.

Security Fix(es):

* requests: Requests vulnerable to .netrc credentials leak via malicious URLs (CVE-2024-47081)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2024-47081
Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. python-requests-2.25.1-10.el9_6.src.rpm
    MD5: aae64fac03b5261153f88a93e3e3e65b
    SHA-256: df00540a09c389be5c7cb5a29680f56b953ccb73e5a5cd7caa38c49e28ea94f2
    Size: 3.58 MB

Asianux Server 9 for x86_64
  1. python3-requests-2.25.1-10.el9_6.noarch.rpm
    MD5: bd5550e53f8a8dd4418ea13bc1d479b7
    SHA-256: d47b785d8a85081dbf8d56122d2fe8ed0987f76899c15ece4fabd111880f1d0f
    Size: 130.17 kB
  2. python3-requests+security-2.25.1-10.el9_6.noarch.rpm
    MD5: 3a2221140b92cb7155ba3c98ae5174e0
    SHA-256: 6d05de7d59135933665d9538f05bc860bdd2b2f6f0372111112996fa667d156c
    Size: 7.99 kB
  3. python3-requests+socks-2.25.1-10.el9_6.noarch.rpm
    MD5: 1340d4e2004f66017cd32f2957a7b50b
    SHA-256: 9c5b9cc20d073924665c8f4643d26baecdc355f554cfa5c205f4804d3d0658b6
    Size: 8.11 kB