Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump requests version to latest stable #71

Merged
merged 1 commit into from
Jun 1, 2023
Merged

Bump requests version to latest stable #71

merged 1 commit into from
Jun 1, 2023

Conversation

saidmasoud
Copy link
Contributor

Addresses security vulnerability. Verified exporter still works with newer version. From release notes:

Versions of Requests between v2.3.0 and v2.30.0 are vulnerable to potential
forwarding of Proxy-Authorization headers to destination servers when
following HTTPS redirects.

When proxies are defined with user info (https://user:pass@proxy:8080/), Requests
will construct a Proxy-Authorization header that is attached to the request to
authenticate with the proxy.

In cases where Requests receives a redirect response, it previously reattached
the Proxy-Authorization header incorrectly, resulting in the value being
sent through the tunneled connection to the destination server. Users who rely on
defining their proxy credentials in the URL are strongly encouraged to upgrade
to Requests 2.31.0+ to prevent unintentional leakage and rotate their proxy
credentials once the change has been fully deployed.

Users who do not use a proxy or do not supply their proxy credentials through
the user information portion of their proxy URL are not subject to this
vulnerability.

Full details can be read in our Github Security Advisory
and CVE-2023-32681.

Copy link
Owner

@phsmith phsmith left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@saidmasoud Thank you for your contribution and for addressing the issue of the request library.

@phsmith phsmith merged commit 230dfbc into phsmith:main Jun 1, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants