CVE Vulnerabilities

CVE-2024-47081

Insufficiently Protected Credentials

Published: Jun 09, 2025 | Modified: Jun 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with trust_env=False on ones Requests Session.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10RedHatpython-requests-0:2.32.4-1.el10_0*
Red Hat Enterprise Linux 8RedHatfence-agents-0:4.2.1-129.el8_10.14*
Red Hat Enterprise Linux 8RedHatresource-agents-0:4.9.0-54.el8_10.16*
Red Hat Enterprise Linux 8RedHatpython-requests-0:2.20.0-6.el8_10*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatpython-requests-0:2.20.0-3.el8_2*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatfence-agents-0:4.2.1-65.el8_4.21*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatresource-agents-0:4.1.1-90.el8_4.20*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatpython-requests-0:2.20.0-3.el8_4*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatfence-agents-0:4.2.1-65.el8_4.21*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatresource-agents-0:4.1.1-90.el8_4.20*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatpython-requests-0:2.20.0-3.el8_4*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatfence-agents-0:4.2.1-89.el8_6.15*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatpython-requests-0:2.20.0-3.el8_6.1*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatfence-agents-0:4.2.1-89.el8_6.15*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatresource-agents-0:4.9.0-16.el8_6.17*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatpython-requests-0:2.20.0-3.el8_6.1*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatfence-agents-0:4.2.1-89.el8_6.15*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatresource-agents-0:4.9.0-16.el8_6.17*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatpython-requests-0:2.20.0-3.el8_6.1*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatfence-agents-0:4.2.1-112.el8_8.11*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatresource-agents-0:4.9.0-40.el8_8.11*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatpython-requests-0:2.20.0-3.el8_8.1*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatfence-agents-0:4.2.1-112.el8_8.11*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatresource-agents-0:4.9.0-40.el8_8.11*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatpython-requests-0:2.20.0-3.el8_8.1*
Red Hat Enterprise Linux 9RedHatpython-requests-0:2.25.1-10.el9_6*
Red Hat Enterprise Linux 9RedHatpython-requests-0:2.25.1-10.el9_6*
Python-pipUbuntuesm-apps/jammy*
Python-pipUbuntuesm-apps/noble*
Python-pipUbuntujammy*
Python-pipUbuntunoble*
Python-pipUbuntuoracular*
Python-pipUbuntuplucky*
RequestsUbuntudevel*
RequestsUbuntuesm-infra-legacy/trusty*
RequestsUbuntuesm-infra/bionic*
RequestsUbuntuesm-infra/focal*
RequestsUbuntuesm-infra/xenial*
RequestsUbuntujammy*
RequestsUbuntunoble*
RequestsUbuntuoracular*
RequestsUbuntuplucky*
RequestsUbuntuquesting*
RequestsUbuntuupstream*

Potential Mitigations

References