CVE Vulnerabilities

CVE-2024-47081

Insufficiently Protected Credentials

Published: Jun 09, 2025 | Modified: Jun 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM

Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with trust_env=False on ones Requests Session.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Red Hat Enterprise Linux 10 RedHat python-requests-0:2.32.4-1.el10_0 *
Red Hat Enterprise Linux 8 RedHat fence-agents-0:4.2.1-129.el8_10.14 *
Red Hat Enterprise Linux 8 RedHat resource-agents-0:4.9.0-54.el8_10.16 *
Red Hat Enterprise Linux 8 RedHat python-requests-0:2.20.0-6.el8_10 *
Red Hat Enterprise Linux 8.2 Advanced Update Support RedHat python-requests-0:2.20.0-3.el8_2 *
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support RedHat fence-agents-0:4.2.1-65.el8_4.21 *
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support RedHat resource-agents-0:4.1.1-90.el8_4.20 *
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support RedHat python-requests-0:2.20.0-3.el8_4 *
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On RedHat fence-agents-0:4.2.1-65.el8_4.21 *
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On RedHat resource-agents-0:4.1.1-90.el8_4.20 *
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On RedHat python-requests-0:2.20.0-3.el8_4 *
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support RedHat fence-agents-0:4.2.1-89.el8_6.15 *
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support RedHat python-requests-0:2.20.0-3.el8_6.1 *
Red Hat Enterprise Linux 8.6 Telecommunications Update Service RedHat fence-agents-0:4.2.1-89.el8_6.15 *
Red Hat Enterprise Linux 8.6 Telecommunications Update Service RedHat resource-agents-0:4.9.0-16.el8_6.17 *
Red Hat Enterprise Linux 8.6 Telecommunications Update Service RedHat python-requests-0:2.20.0-3.el8_6.1 *
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions RedHat fence-agents-0:4.2.1-89.el8_6.15 *
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions RedHat resource-agents-0:4.9.0-16.el8_6.17 *
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions RedHat python-requests-0:2.20.0-3.el8_6.1 *
Red Hat Enterprise Linux 8.8 Telecommunications Update Service RedHat fence-agents-0:4.2.1-112.el8_8.11 *
Red Hat Enterprise Linux 8.8 Telecommunications Update Service RedHat resource-agents-0:4.9.0-40.el8_8.11 *
Red Hat Enterprise Linux 8.8 Telecommunications Update Service RedHat python-requests-0:2.20.0-3.el8_8.1 *
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions RedHat fence-agents-0:4.2.1-112.el8_8.11 *
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions RedHat resource-agents-0:4.9.0-40.el8_8.11 *
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions RedHat python-requests-0:2.20.0-3.el8_8.1 *
Red Hat Enterprise Linux 9 RedHat python-requests-0:2.25.1-10.el9_6 *
Red Hat Enterprise Linux 9 RedHat python-requests-0:2.25.1-10.el9_6 *
Python-pip Ubuntu devel *
Python-pip Ubuntu esm-apps/bionic *
Python-pip Ubuntu esm-apps/focal *
Python-pip Ubuntu esm-apps/jammy *
Python-pip Ubuntu esm-apps/noble *
Python-pip Ubuntu esm-apps/xenial *
Python-pip Ubuntu esm-infra-legacy/trusty *
Python-pip Ubuntu jammy *
Python-pip Ubuntu noble *
Python-pip Ubuntu oracular *
Python-pip Ubuntu plucky *
Requests Ubuntu devel *
Requests Ubuntu esm-infra-legacy/trusty *
Requests Ubuntu esm-infra/bionic *
Requests Ubuntu esm-infra/focal *
Requests Ubuntu esm-infra/xenial *
Requests Ubuntu jammy *
Requests Ubuntu noble *
Requests Ubuntu oracular *
Requests Ubuntu plucky *
Requests Ubuntu upstream *

Potential Mitigations

References