Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests Session, if the first request is made with verify=False to disable cert verification, all subsequent requests to the same host will continue to ignore cert verification regardless of changes to the value of verify. This behavior will continue for the lifecycle of the connection in the connection pool. This vulnerability is fixed in 2.32.0.
The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Ansible Automation Platform 2.4 for RHEL 8 | RedHat | python3x-requests-0:2.32.2-1.el8ap | * |
| Red Hat Ansible Automation Platform 2.4 for RHEL 8 | RedHat | automation-controller-0:4.5.8-1.el8ap | * |
| Red Hat Ansible Automation Platform 2.4 for RHEL 9 | RedHat | python-requests-0:2.32.2-1.el9ap | * |
| Red Hat Ansible Automation Platform 2.4 for RHEL 9 | RedHat | automation-controller-0:4.5.8-1.el9ap | * |
| Red Hat Developer Hub 1.2 on RHEL 9 | RedHat | rhdh/rhdh-hub-rhel9:1.2-105 | * |
| Red Hat Enterprise Linux 8 | RedHat | python-requests-0:2.20.0-5.el8_10 | * |
| Red Hat Enterprise Linux 9 | RedHat | python-requests-0:2.25.1-9.el9 | * |
| Red Hat Enterprise Linux 9 | RedHat | python-requests-0:2.25.1-9.el9 | * |
| Red Hat OpenStack Platform 17.1 for RHEL 8 | RedHat | python-requests-0:2.25.1-2.el8ost | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | candlepin-0:4.4.21-1.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | foreman-0:3.12.0.6-1.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | foreman-installer-1:3.12.0.4-2.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | python-django-0:4.2.19-1.el8pc | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | python-jinja2-0:3.1.5-1.el8pc | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | python-pulp-cli-0:0.29.2-2.el8pc | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | python-pulp-container-0:2.20.5-1.el8pc | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | python-pulpcore-0:3.49.33-1.el8pc | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | python-pulp-glue-0:0.29.2-2.el8pc | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | python-requests-0:2.32.3-2.el8pc | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | rubygem-foreman_ansible-0:14.2.3-1.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | rubygem-foreman_maintain-1:1.7.12-1.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | rubygem-foreman_openscap-0:9.0.5-1.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | rubygem-foreman_remote_execution-0:13.2.7-1.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | rubygem-foreman_theme_satellite-0:13.3.5-1.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | rubygem-katello-0:4.14.0.8-1.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | satellite-0:6.16.3-2.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | scap-security-guide-satellite-0:1.0.0-1.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | candlepin-0:4.4.21-1.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | foreman-0:3.12.0.6-1.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | foreman-installer-1:3.12.0.4-2.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | python-django-0:4.2.19-1.el8pc | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | python-jinja2-0:3.1.5-1.el8pc | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | python-pulp-cli-0:0.29.2-2.el8pc | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | python-pulp-container-0:2.20.5-1.el8pc | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | python-pulpcore-0:3.49.33-1.el8pc | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | python-pulp-glue-0:0.29.2-2.el8pc | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | python-requests-0:2.32.3-2.el8pc | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | rubygem-foreman_ansible-0:14.2.3-1.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | rubygem-foreman_maintain-1:1.7.12-1.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | rubygem-foreman_openscap-0:9.0.5-1.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | rubygem-foreman_remote_execution-0:13.2.7-1.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | rubygem-foreman_theme_satellite-0:13.3.5-1.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | rubygem-katello-0:4.14.0.8-1.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | satellite-0:6.16.3-2.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 8 | RedHat | scap-security-guide-satellite-0:1.0.0-1.el8sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | candlepin-0:4.4.21-1.el9sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | foreman-0:3.12.0.6-1.el9sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | foreman-installer-1:3.12.0.4-2.el9sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | python-django-0:4.2.19-1.el9pc | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | python-jinja2-0:3.1.5-1.el9pc | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | python-pulp-cli-0:0.29.2-2.el9pc | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | python-pulp-container-0:2.20.5-1.el9pc | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | python-pulpcore-0:3.49.33-1.el9pc | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | python-pulp-glue-0:0.29.2-2.el9pc | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | python-requests-0:2.32.3-2.el9pc | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | rubygem-foreman_ansible-0:14.2.3-1.el9sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | rubygem-foreman_maintain-1:1.7.12-1.el9sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | rubygem-foreman_openscap-0:9.0.5-1.el9sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | rubygem-foreman_remote_execution-0:13.2.7-1.el9sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | rubygem-foreman_theme_satellite-0:13.3.5-1.el9sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | rubygem-katello-0:4.14.0.8-1.el9sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | satellite-0:6.16.3-2.el9sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | scap-security-guide-satellite-0:1.0.0-1.el9sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | candlepin-0:4.4.21-1.el9sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | foreman-0:3.12.0.6-1.el9sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | foreman-installer-1:3.12.0.4-2.el9sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | python-django-0:4.2.19-1.el9pc | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | python-jinja2-0:3.1.5-1.el9pc | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | python-pulp-cli-0:0.29.2-2.el9pc | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | python-pulp-container-0:2.20.5-1.el9pc | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | python-pulpcore-0:3.49.33-1.el9pc | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | python-pulp-glue-0:0.29.2-2.el9pc | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | python-requests-0:2.32.3-2.el9pc | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | rubygem-foreman_ansible-0:14.2.3-1.el9sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | rubygem-foreman_maintain-1:1.7.12-1.el9sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | rubygem-foreman_openscap-0:9.0.5-1.el9sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | rubygem-foreman_remote_execution-0:13.2.7-1.el9sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | rubygem-foreman_theme_satellite-0:13.3.5-1.el9sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | rubygem-katello-0:4.14.0.8-1.el9sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | satellite-0:6.16.3-2.el9sat | * |
| Red Hat Satellite 6.16 for RHEL 9 | RedHat | scap-security-guide-satellite-0:1.0.0-1.el9sat | * |
| RHUI 4 for RHEL 8 | RedHat | python-requests-0:2.32.3-2.el8ui | * |
| Red Hat Discovery 1.14 | RedHat | discovery/discovery-ui-rhel9:sha256:c960fa13577db72b52765d6941688f431f61fe38adb717b2d8bb6569e241bc5e | * |
| Python-pip | Ubuntu | devel | * |
| Python-pip | Ubuntu | esm-apps/bionic | * |
| Python-pip | Ubuntu | esm-apps/focal | * |
| Python-pip | Ubuntu | esm-apps/jammy | * |
| Python-pip | Ubuntu | esm-apps/noble | * |
| Python-pip | Ubuntu | esm-apps/xenial | * |
| Python-pip | Ubuntu | esm-infra-legacy/trusty | * |
| Python-pip | Ubuntu | focal | * |
| Python-pip | Ubuntu | jammy | * |
| Python-pip | Ubuntu | mantic | * |
| Python-pip | Ubuntu | noble | * |
| Python-pip | Ubuntu | oracular | * |
| Python-pip | Ubuntu | plucky | * |
| Python-pip | Ubuntu | questing | * |
| Python-pip | Ubuntu | trusty/esm | * |
| Requests | Ubuntu | devel | * |
| Requests | Ubuntu | esm-infra-legacy/trusty | * |
| Requests | Ubuntu | esm-infra/bionic | * |
| Requests | Ubuntu | esm-infra/focal | * |
| Requests | Ubuntu | esm-infra/xenial | * |
| Requests | Ubuntu | focal | * |
| Requests | Ubuntu | jammy | * |
| Requests | Ubuntu | mantic | * |
| Requests | Ubuntu | noble | * |
| Requests | Ubuntu | oracular | * |
| Requests | Ubuntu | plucky | * |
| Requests | Ubuntu | questing | * |
| Requests | Ubuntu | trusty/esm | * |