python-requests-2.25.1-10.el9_6
エラータID: AXSA:2025-10695:03
リリース日:
2025/08/05 Tuesday - 14:42
題名:
python-requests-2.25.1-10.el9_6
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
Moderate
Description:
以下項目について対処しました。
[Security Fix]
- python-requests には、URL の解析処理に問題があるため、リモート
の攻撃者により、.netrc に保存された認証情報の漏洩を可能とする
脆弱性が存在します。(CVE-2024-47081)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2024-47081
Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.
Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.
追加情報:
N/A
ダウンロード:
SRPMS
- python-requests-2.25.1-10.el9_6.src.rpm
MD5: aae64fac03b5261153f88a93e3e3e65b
SHA-256: df00540a09c389be5c7cb5a29680f56b953ccb73e5a5cd7caa38c49e28ea94f2
Size: 3.58 MB
Asianux Server 9 for x86_64
- python3-requests-2.25.1-10.el9_6.noarch.rpm
MD5: bd5550e53f8a8dd4418ea13bc1d479b7
SHA-256: d47b785d8a85081dbf8d56122d2fe8ed0987f76899c15ece4fabd111880f1d0f
Size: 130.17 kB - python3-requests+security-2.25.1-10.el9_6.noarch.rpm
MD5: 3a2221140b92cb7155ba3c98ae5174e0
SHA-256: 6d05de7d59135933665d9538f05bc860bdd2b2f6f0372111112996fa667d156c
Size: 7.99 kB - python3-requests+socks-2.25.1-10.el9_6.noarch.rpm
MD5: 1340d4e2004f66017cd32f2957a7b50b
SHA-256: 9c5b9cc20d073924665c8f4643d26baecdc355f554cfa5c205f4804d3d0658b6
Size: 8.11 kB