CVE-2024-35195

Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests `Session`, if the first request is made with `verify=False` to disable cert verification, all subsequent requests to the same host will continue to ignore cert verification regardless of changes to the value of `verify`. This behavior will continue for the lifecycle of the connection in the connection pool. This vulnerability is fixed in 2.32.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.6 MEDIUM
LOCAL
HIGH
HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N
GitHub_MCNA
5.6 MEDIUM
LOCAL
HIGH
HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N
CISA-ADPADP
---
---
CVEADP
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 2%
Debian logo
Debian Releases
Debian Product
Codename
requests
bullseye
no-dsa
bookworm
no-dsa
buster
postponed
sid
2.32.3+dfsg-5
fixed
trixie
2.32.3+dfsg-5
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-pip
plucky
needed
oracular
needed
noble
needed
mantic
ignored
jammy
needed
focal
ignored
bionic
ignored
xenial
ignored
trusty
ignored
requests
plucky
Fixed 2.32.3+dfsg-1ubuntu1
released
oracular
Fixed 2.32.3+dfsg-1ubuntu1
released
noble
ignored
mantic
ignored
jammy
ignored
focal
ignored
bionic
ignored
xenial
ignored
trusty
ignored