DEBIAN-CVE-2024-47081

Source
https://security-tracker.debian.org/tracker/CVE-2024-47081
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-47081.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2024-47081
Upstream
Published
2025-06-09T18:15:24Z
Modified
2025-09-25T07:43:17.063358Z
Summary
[none]
Details

Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with trust_env=False on one's Requests Session.

References

Affected packages

Debian:11 / requests

Package

Name
requests
Purl
pkg:deb/debian/requests?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.25.1+dfsg-2
2.27.1+dfsg-1
2.28.1+dfsg-1
2.31.0+dfsg-1
2.31.0+dfsg-2
2.32.3+dfsg-1
2.32.3+dfsg-2
2.32.3+dfsg-3
2.32.3+dfsg-4
2.32.3+dfsg-5
2.32.4+dfsg-1
2.32.5+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / requests

Package

Name
requests
Purl
pkg:deb/debian/requests?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.28.1+dfsg-1
2.31.0+dfsg-1
2.31.0+dfsg-2
2.32.3+dfsg-1
2.32.3+dfsg-2
2.32.3+dfsg-3
2.32.3+dfsg-4
2.32.3+dfsg-5
2.32.4+dfsg-1
2.32.5+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / requests

Package

Name
requests
Purl
pkg:deb/debian/requests?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.32.3+dfsg-5
2.32.4+dfsg-1
2.32.5+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / requests

Package

Name
requests
Purl
pkg:deb/debian/requests?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.32.4+dfsg-1

Affected versions

2.*

2.32.3+dfsg-5

Ecosystem specific

{
    "urgency": "not yet assigned"
}