CVE-2024-47081
Requests vulnerable to .netrc credentials leak via malicious URLs
5.3
MEDIUM
CVSS 3.1
EPSS 0.21%
Description
Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session.
How to fix CVE-2024-47081
To remediate CVE-2024-47081, upgrade the affected package to a fixed version below.
- —upgrade to 2.32.4-r0 or later
- —no fix listed
- —upgrade to 2.32.4 or later
Is CVE-2024-47081 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 2.32.4-r0
- from 0
- from 0, < 2.32.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N |