Publishing details

Changelog

requests (2.2.1-1ubuntu0.1) trusty-security; urgency=medium

  * SECURITY UPDATE: Authorization header disclosure on redirect
    - debian/patches/CVE-2014-1829.patch: if redirected, strip
      authentication header in requests/sessions.py, add
      should_bypass_proxies() to requests/utils.py.
    - CVE-2014-1829
  * SECURITY UPDATE: Proxy-Authorization header disclosure on redirect
    - debian/patches/CVE-2014-1830.patch: also strip proxy headers in
      requests/sessions.py, added test to test_requests.py.
    - CVE-2014-1830
 -- Marc Deslauriers <email address hidden>   Tue, 30 Sep 2014 16:13:52 -0400

Available diffs

Builds

Package files