Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
* bsc#1211674 Cross-References: * CVE-2023-32681 . # Security update for python-requests Announcement ID: SUSE-SU-2024:2685-1 Rating: moderate References: * bsc#1211674 Cross-References: * CVE-2023-32681 CVSS scores: * CVE-2023-32681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2023-32681 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N Affected Products: * openSUSE Leap Micro 5.3 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Real Time 15 SP3 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves one vulnerability can now be installed. ## Description: This update for python-requests fixes the following issues: * CVE-2023-32681: Fixed unintended leak of Proxy-Authorization header (bsc#1211674). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap Micro 5.3 zypper in -t patch openSUSE-Leap-Micro-5.3-2024-2685=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-2685=1 * SUSE Linux Enterprise Real Time 15 SP3 zypper in -t patch SUSE-2024-2685=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-2685=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-2685=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-2685=1 ## Package List: * openSUSE Leap Micro 5.3 (noarch) * python3-requests-2.24.0-150300.3.3.1 * SUSE Linux Enterprise High PerformanceComputing LTSS 15 SP3 (noarch) * python3-requests-2.24.0-150300.3.3.1 * SUSE Linux Enterprise Real Time 15 SP3 (noarch) * python3-requests-2.24.0-150300.3.3.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (noarch) * python3-requests-2.24.0-150300.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * python3-requests-2.24.0-150300.3.3.1 * SUSE Enterprise Storage 7.1 (noarch) * python3-requests-2.24.0-150300.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2023-32681.html * https://bugzilla.suse.com/show_bug.cgi?id=1211674 . A recent security update for the python-requests package on SUSE addresses vulnerabilities linked to CVE-2023-32681, highlighting the need for prompt system updates. python-requests Update,SUSE Security Advisory,Software Patch,Security Updates,Proxy Leak Fix. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-4520 https://linux.oracle.com/errata/ELSA-2023-4520.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: python3-requests-2.20.0-3.el8_8.noarch.rpm aarch64: python3-requests-2.20.0-3.el8_8.noarch.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//python-requests-2.20.0-3.el8_8.src.rpm Related CVEs: CVE-2023-32681 Description of changes: [2.20.0-3] - Fix Unintended leak of Proxy-Authorization header (CVE-2023-32681) _______________________________________________ El-errata mailing list
An update for python-requests is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: python-requests security update Advisory ID: RHSA-2023:4350-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:4350 Issue date: 2023-08-01 CVE Names: CVE-2023-32681 ===================================================================== 1. Summary: An update for python-requests is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - noarch Red Hat Enterprise Linux BaseOS (v. 9) - noarch 3. Description: The python-requests package contains a library designed to make HTTP requests easy for developers. Security Fix(es): * python-requests: Unintended leak of Proxy-Authorization header (CVE-2023-32681) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2209469 - CVE-2023-32681 python-requests: Unintended leak of Proxy-Authorization header 6. Package List: Red Hat Enterprise Linux AppStream (v.9): noarch: python3-requests+security-2.25.1-7.el9_2.noarch.rpm python3-requests+socks-2.25.1-7.el9_2.noarch.rpm Red Hat Enterprise Linux BaseOS (v. 9): Source: python-requests-2.25.1-7.el9_2.src.rpm noarch: python3-requests-2.25.1-7.el9_2.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-32681 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJkyRTsAAoJENzjgjWX9erEU4AP/16Fa0Oaj9KCTbQr/zNZ+s3I okLWs8KH6W2eiF8NqeeKPf7/R0uCDjl+dgNMHR4ZSQzfmKsY1HQe0Uq8CHevAWJL 66PDIyxpJZZZ/vzMx5lmSZbnAcrwjA9pumboa9YqRkPCAZf59Af9SuythGKxdv4q ltmwaVpXiEpZ7MimSc5oqfea+3gAQgePppQB7jg3lIdXgl8YGf8pnHFUjsICVveJ YZ/XGDRkG0tJx+AhNlkRwEEZUuMWDEeIdv32l43PkxR7i0UbBYgEC3hZdP2J4wLo MfP9QrEj1W+LhYluhLNe3Yj7iHOVSYfzf4SQkqeRCv3AadeNRQlfxBE/s+WlG6xE wQlKhiD+s0Y3XQfQwSIY+qB7aVEWYhyReUmL6kehmFUxW0WSHHEGbq6AAAyTjC2Y Tj2NCKLcTqkwCg+iUVzkjG5JwvWNjspN9FkAIY0plbHogWgfNFJ1arzBQghW3a3O fD8IeWxNSigo8yXirKPfH4x7WHXEWnW2ISGgamCsI1FxC9GZe49WGnxerD4YosIw RuwsRNknqCe6xara0NLhHJj+IA4V1ldIenNJC4LvvVGruxGzUhyigzbu3NMjJDxP O/hP0rz+DLU1MKdQSoyNYzIGq3R8mqeBu0efoWx7z2E8E2tgKbujSgfFx0QP5ztY bm+MjCCftFTN2LfNf1Ff =q/ez -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.