CVE-2024-47081
ADVISORY - githubSummary
Impact
Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs.
Workarounds
For older versions of Requests, use of the .netrc file can be disabled with trust_env=False
on your Requests Session (docs).
References
https://github.com/psf/requests/pull/6965 https://seclists.org/fulldisclosure/2025/Jun/2
Common Weakness Enumeration (CWE)
Insufficiently Protected Credentials
Insufficiently Protected Credentials
NIST
1.6
CVSS SCORE
5.3mediumGitHub
1.6
CVSS SCORE
5.3mediumAlpine
-
Debian
-
Ubuntu
-
CVSS SCORE
N/AmediumAlma
-
CVSS SCORE
N/AmediumAlma
-
CVSS SCORE
N/AmediumAlma
-
CVSS SCORE
N/AmediumAmazon
-
CVSS SCORE
N/AmediumAmazon
-
CVSS SCORE
N/AmediumAmazon
-
CVSS SCORE
N/AmediumAmazon
-
CVSS SCORE
N/AmediumAmazon
-
CVSS SCORE
N/AmediumAmazon
-
CVSS SCORE
N/AmediumRocky
-
CVSS SCORE
N/AlowRocky
-
CVSS SCORE
N/AlowRocky
-
CVSS SCORE
N/AlowOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumOracle
-
CVSS SCORE
N/AmediumChainguard
CGA-24q3-6wm3-783c
-
Chainguard
CGA-28fq-h8q6-3fvj
-
Chainguard
CGA-38hg-g75q-gh5p
-
Chainguard
CGA-398v-hm2p-xw79
-
Chainguard
CGA-4754-mrr3-695h
-
Chainguard
CGA-55pq-6583-9c43
-
Chainguard
CGA-578p-xq4j-24jg
-
Chainguard
CGA-57rv-3w6v-vfm6
-
Chainguard
CGA-58x2-w6m9-pqfx
-
Chainguard
CGA-6gx6-w6wf-qcv3
-
Chainguard
CGA-6r3c-fq5f-jjfh
-
Chainguard
CGA-7x96-xhvp-q5g8
-
Chainguard
CGA-892p-h54v-f7fc
-
Chainguard
CGA-93q6-5vch-j6xg
-
Chainguard
CGA-954m-ppvf-6f35
-
Chainguard
CGA-99hv-7qh4-6g5w
-
Chainguard
CGA-9rjg-3x9h-x532
-
Chainguard
CGA-9rrq-6vw7-gg88
-
Chainguard
CGA-9w68-hrgc-76hj
-
Chainguard
CGA-c2r7-2566-pwm6
-
Chainguard
CGA-c5vr-px9j-7fpg
-
Chainguard
CGA-cff4-qq7g-q7cr
-
Chainguard
CGA-cvpx-m598-wh5q
-
Chainguard
CGA-f4rp-xqp9-8fgg
-
Chainguard
CGA-fxjq-g46f-7r8q
-
Chainguard
CGA-g8fj-8q2m-xr96
-
Chainguard
CGA-h2m6-v7c4-gf9v
-
Chainguard
CGA-hf94-r6q8-78mp
-
Chainguard
CGA-j29g-9w34-j25c
-
Chainguard
CGA-j43x-47vc-4gwp
-
Chainguard
CGA-j4hh-xq5f-87rc
-
Chainguard
CGA-j4hw-v6wc-vrhh
-
Chainguard
CGA-j4pw-wrph-m6cg
-
Chainguard
CGA-jgvj-g2p4-w9wq
-
Chainguard
CGA-jmr7-vvhv-6h2m
-
Chainguard
CGA-jpf3-6439-4v4p
-
Chainguard
CGA-m7px-9925-hv89
-
Chainguard
CGA-mg8p-7vfh-73jf
-
Chainguard
CGA-mm5x-7qfp-q7fp
-
Chainguard
CGA-pcg9-4mrr-wqmg
-
Chainguard
CGA-r73w-4q8h-cxgr
-
Chainguard
CGA-rph5-7mmf-v92v
-
Chainguard
CGA-rq3q-962h-6765
-
Chainguard
CGA-vhc6-vwgp-f96x
-
Chainguard
CGA-vmhc-65h4-42pm
-
Chainguard
CGA-vq42-r69c-q22r
-
Chainguard
CGA-w6mm-6v55-whrm
-
Chainguard
CGA-xgx2-r76q-v9mw
-
Chainguard
CGA-xwjr-j6q5-vv6m
-
minimos
MINI-4264-8x7m-ffv5
-
minimos
MINI-577q-gwpm-5335
-
minimos
MINI-66x3-p8j6-jx66
-
minimos
MINI-9j85-x99w-c53f
-
minimos
MINI-r9pq-9c7c-f6xq
-