Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
* bsc#1224788 * bsc#1226321 * bsc#1231500 Cross-References: . # Security update for python-requests Announcement ID: SUSE-SU-2025:20094-1 Release Date: 2025-02-03T09:12:09Z Rating: moderate References: * bsc#1224788 * bsc#1226321 * bsc#1231500 Cross-References: * CVE-2024-35195 CVSS scores: * CVE-2024-35195 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability and has two fixes can now be installed. ## Description: This update for python-requests contains the following fixes: * Add patch to fix to inject the default CA bundles if they are not specified. (bsc#1226321, bsc#1231500) * Remove Requires on python-py, it should have been removed earlier. * update to 2.32.3: * Fixed bug breaking the ability to specify custom SSLContexts in sub-classes of HTTPAdapter. * Fixed issue where Requests started failing to run on Python versions compiled without the `ssl` module. * To provide a more stable migration for custom HTTPAdapters impacted by the CVE changes in 2.32.0, we've renamed _get_connection to a new public API, get_connection_with_tls_context. Existing custom HTTPAdapters will need to migrate their code to use this new API. get_connection is * Fixed an issue where setting verify=False on the first request from a Session will cause subsequent requests to the same origin to also ignore cert verification, * verify=True now reuses a global SSLContext which should improve request time * Requests now supports optional use of character detection (chardet or charset_normalizer) when repackaged or vendored. This enables pip and other projects to minimize their ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patchSUSE-SLE-Micro-6.0-125=1 ## Package List: * SUSE Linux Micro 6.0 (noarch) * python311-requests-2.32.3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-35195.html * https://bugzilla.suse.com/show_bug.cgi?id=1224788 * https://bugzilla.suse.com/show_bug.cgi?id=1226321 * https://bugzilla.suse.com/show_bug.cgi?id=1231500 . An enhancement patch for python-requests in SUSE Linux Micro 6.0 addresses moderate risk vulnerabilities, boosting overall reliability.. SUSE Linux Micro, python requests security, CVE-2024-35195, patches for SUSE. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-4520 https://linux.oracle.com/errata/ELSA-2023-4520.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: python3-requests-2.20.0-3.el8_8.noarch.rpm aarch64: python3-requests-2.20.0-3.el8_8.noarch.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//python-requests-2.20.0-3.el8_8.src.rpm Related CVEs: CVE-2023-32681 Description of changes: [2.20.0-3] - Fix Unintended leak of Proxy-Authorization header (CVE-2023-32681) _______________________________________________ El-errata mailing list
Forwarding proxy credentials to the destination server unintentionally (CVE-2023-32681) References: - https://bugs.mageia.org/show_bug.cgi?id=32032 . MGASA-2023-0210 - Updated python-requests packages fix security vulnerability Publication date: 28 Jun 2023 URL: https://advisories.mageia.org/MGASA-2023-0210.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-32681 Forwarding proxy credentials to the destination server unintentionally (CVE-2023-32681) References: - https://bugs.mageia.org/show_bug.cgi?id=32032 - https://lists.debian.org/debian-lts-announce/2023/06/msg00018.html - https://ubuntu.com/security/notices/USN-6155-1 - https://www.cve.org/CVERecord?id=CVE-2023-32681 SRPMS: - 8/core/python-requests-2.25.1-1.2.mga8 . MGASA-2023-0211 addresses a vulnerability in python-urllib3 to remediate severe credential leakage risk on Mageia.. Mageia Security Update, Python Requests Vulnerability, Credential Exposure Fix. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.