FlawAtlas
Search the atlas
SUSE-SU-2020:1792-1 Not scored

Security update for python3-requests

This update for python3-requests provides the following fix: python-requests was updated to 2.20.1. Update to version 2.20.1: * Fixed bug with unintended Authorization header stripping for redirects using default ports (http/80, https/443). Update to version 2.20.0: * Bugfixes + Content-Type header parsing is now case-insensitive (e.g. charset=utf8 v Charset=utf8). + Fixed exception leak where certain redirect urls would raise uncaught urllib3 exceptions. + Requests removes Authorization header from requests redirected from https to http on the same hostname. (CVE-2018-18074) + should_bypass_proxies now handles URIs without hostnames (e.g. files). Update to version 2.19.1: * Fixed issue where status_codes.py’s init function failed trying to append to a __doc__ value of None. Update to version 2.19.0: * Improvements + Warn about possible slowdown with cryptography version < 1.3.4 + Check host in proxy URL, before forwarding request to adapter. + Maintain fragments properly across redirects. (RFC7231 7.1.2) + Removed use of cgi module to expedite library load time. + Added support for SHA-256 and SHA-512 digest auth algorithms. + Minor performance improvement to Request.content. * Bugfixes + Parsing empty Link headers with parse_header_links() no longer return one bogus entry. + Fixed issue where loading the default certificate bundle from a zip archive would raise an IOError. + Fixed issue with unexpected ImportError on windows system which do not support winreg module. + DNS resolution in proxy bypass no longer includes the username and password in the request. This also fixes the issue of DNS queries failing on macOS. + Properly normalize adapter prefixes for url comparison. + Passing None as a file pointer to the files param no longer raises an exception. + Calling copy on a RequestsCookieJar will now preserve the cookie policy correctly. Update to version 2.18.4: * Improvements + Error messages for invalid headers now include the header name for easier debugging Update to version 2.18.3: * Improvements + Running $ python -m requests.help now includes the installed version of idna. * Bugfixes + Fixed issue where Requests would raise ConnectionError instead of SSLError when encountering SSL problems when using urllib3 v1.22. - Add ca-certificates (and ca-certificates-mozilla) to dependencies, otherwise https connections will fail.

Exploit probability Not scored
Published June 26, 2020
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:OpenStack Cloud 8 python-chardet
SUSE:Linux Enterprise Server for SAP Applications 12 SP5 python-chardet
SUSE:Linux Enterprise Server 12 SP3-BCL python-urllib3
SUSE:Linux Enterprise Server for SAP Applications 12 SP3 python-chardet
SUSE:Linux Enterprise Server for SAP Applications 12 SP5 python3-requests
SUSE:OpenStack Cloud 7 python3-requests
SUSE:Linux Enterprise Module for Public Cloud 12 python-certifi
SUSE:OpenStack Cloud 8 python-certifi
SUSE:Enterprise Storage 5 python3-requests
SUSE:Enterprise Storage 5 python-chardet
SUSE:Linux Enterprise Server 12 SP3-BCL python-chardet
SUSE:Linux Enterprise Module for Public Cloud 12 python-urllib3
SUSE:Linux Enterprise Server 12 SP4 python-certifi
SUSE:Linux Enterprise Server for SAP Applications 12 SP2 python-chardet
SUSE:OpenStack Cloud Crowbar 8 python3-requests
SUSE:Manager Proxy 3.2 python-certifi
SUSE:Linux Enterprise Server for SAP Applications 12 SP5 python-urllib3
SUSE:Linux Enterprise Server for SAP Applications 12 SP3 python3-requests
SUSE:Linux Enterprise Server 12 SP3-BCL python-certifi
SUSE:Linux Enterprise Server 12 SP3-BCL python3-requests
SUSE:Linux Enterprise Server for SAP Applications 12 SP4 python3-requests
SUSE:HPE Helion OpenStack 8 python-urllib3
SUSE:Linux Enterprise Server for SAP Applications 12 SP3 python-certifi
SUSE:Linux Enterprise Server for SAP Applications 12 SP2 python-urllib3
SUSE:Linux Enterprise Server 12 SP3-LTSS python-certifi
SUSE:Linux Enterprise Server 12 SP2-LTSS python-chardet
SUSE:Linux Enterprise Server 12 SP4 python-urllib3
SUSE:Linux Enterprise Server 12 SP3-LTSS python-urllib3
SUSE:Linux Enterprise Software Development Kit 12 SP5 python3-requests
SUSE:Linux Enterprise Server for SAP Applications 12 SP4 python-certifi
SUSE:Manager Server 3.2 python3-requests
SUSE:Linux Enterprise Server 12 SP5 python-urllib3
SUSE:Linux Enterprise Server 12 SP5 python3-requests
SUSE:OpenStack Cloud Crowbar 8 python-chardet
SUSE:Linux Enterprise Server for SAP Applications 12 SP2 python-certifi
SUSE:Linux Enterprise Software Development Kit 12 SP5 python-urllib3
SUSE:Linux Enterprise Server 12 SP3-LTSS python-chardet
SUSE:Linux Enterprise Server for SAP Applications 12 SP3 python-urllib3
SUSE:Manager Proxy 3.2 python-urllib3
SUSE:Manager Proxy 3.2 python3-requests
SUSE:OpenStack Cloud Crowbar 8 python-certifi
SUSE:Linux Enterprise Server 12 SP5 python-chardet
SUSE:HPE Helion OpenStack 8 python3-requests
SUSE:Linux Enterprise Workstation Extension 12 SP5 python-chardet
SUSE:Linux Enterprise Software Development Kit 12 SP5 python-chardet
SUSE:Linux Enterprise Server for SAP Applications 12 SP2 python3-requests
SUSE:OpenStack Cloud 7 python-urllib3
SUSE:Manager Proxy 3.2 python-chardet
SUSE:OpenStack Cloud 8 python-urllib3
SUSE:Manager Server 3.2 python-chardet
SUSE:Linux Enterprise Workstation Extension 12 SP5 python-certifi
SUSE:HPE Helion OpenStack 8 python-chardet
SUSE:Enterprise Storage 5 python-urllib3
SUSE:Enterprise Storage 5 python-certifi
SUSE:Linux Enterprise Server for SAP Applications 12 SP4 python-urllib3
SUSE:Linux Enterprise Server 12 SP2-BCL python-urllib3
SUSE:Linux Enterprise Workstation Extension 12 SP5 python3-requests
SUSE:Linux Enterprise Server 12 SP4 python3-requests
SUSE:Linux Enterprise Server for SAP Applications 12 SP4 python-chardet
SUSE:Linux Enterprise Server 12 SP2-LTSS python3-requests
SUSE:Linux Enterprise Server 12 SP2-LTSS python-certifi
SUSE:OpenStack Cloud 7 python-certifi
SUSE:Linux Enterprise Server for SAP Applications 12 SP5 python-certifi
SUSE:OpenStack Cloud Crowbar 8 python-urllib3
SUSE:Linux Enterprise Server 12 SP3-LTSS python3-requests
SUSE:Linux Enterprise Module for Public Cloud 12 python-chardet
SUSE:HPE Helion OpenStack 8 python-certifi
SUSE:Linux Enterprise Server 12 SP2-BCL python3-requests
SUSE:OpenStack Cloud 8 python3-requests
SUSE:OpenStack Cloud 7 python-chardet
SUSE:Linux Enterprise Server 12 SP4 python-chardet
SUSE:Linux Enterprise Server 12 SP5 python-certifi
SUSE:Manager Server 3.2 python-certifi
SUSE:Manager Server 3.2 python-urllib3
SUSE:Linux Enterprise Workstation Extension 12 SP5 python-urllib3
SUSE:Linux Enterprise Server 12 SP2-BCL python-chardet
SUSE:Linux Enterprise Software Development Kit 12 SP5 python-certifi
SUSE:Linux Enterprise Server 12 SP2-LTSS python-urllib3
SUSE:Linux Enterprise Server 12 SP2-BCL python-certifi

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2020:1792-1

This update for python3-requests provides the following fix: python-requests was updated to 2.20.1. Update to version 2.20.1: * Fixed bug with unintended Authorization header stripping for redirects using default ports (http/80, https/443). Update to version 2.20.0: * Bugfixes + Content-Type header parsing is now case-insensitive (e.g. charset=utf8 v Charset=utf8). + Fixed exception leak where certain redirect urls would raise uncaught urllib3 exceptions. + Requests removes Authorization header from requests redirected from https to http on the same hostname. (CVE-2018-18074) + should_bypass_proxies now handles URIs without hostnames (e.g. files). Update to version 2.19.1: * Fixed issue where status_codes.py’s init function failed trying to append to a __doc__ value of None. Update to version 2.19.0: * Improvements + Warn about possible slowdown with cryptography version < 1.3.4 + Check host in proxy URL, before forwarding request to adapter. + Maintain fragments properly across redirects. (RFC7231 7.1.2) + Removed use of cgi module to expedite library load time. + Added support for SHA-256 and SHA-512 digest auth algorithms. + Minor performance improvement to Request.content. * Bugfixes + Parsing empty Link headers with parse_header_links() no longer return one bogus entry. + Fixed issue where loading the default certificate bundle from a zip archive would raise an IOError. + Fixed issue with unexpected ImportError on windows system which do not support winreg module. + DNS resolution in proxy bypass no longer includes the username and password in the request. This also fixes the issue of DNS queries failing on macOS. + Properly normalize adapter prefixes for url comparison. + Passing None as a file pointer to the files param no longer raises an exception. + Calling copy on a RequestsCookieJar will now preserve the cookie policy correctly. Update to version 2.18.4: * Improvements + Error messages for invalid headers now include the header name for easier debugging Update to version 2.18.3: * Improvements + Running $ python -m requests.help now includes the installed version of idna. * Bugfixes + Fixed issue where Requests would raise ConnectionError instead of SSLError when encountering SSL problems when using urllib3 v1.22. - Add ca-certificates (and ca-certificates-mozilla) to dependencies, otherwise https connections will fail.

View original source

05 / REFERENCES

Further evidence