Incorrect control flow implementation in requests library (CVE-2024-35195) #shorts #breaking
CVE
In May 2024, a new vulnerability was reported in the popular Requests library, identified as CVE-2024-35195. This vulnerability stems from an incorrect control flow implementation within the library. Although no specific attacks have been reported yet, this flaw is significant as it affects all versions of the Requests library prior to 2.32.0. The main concern is that it allows potential attackers to bypass SSL certificate verification, posing serious security risks for users of the library. This vulnerability is particularly concerning for all users relying on the Requests library for secure HTTP communications.
Watch the full video on YouTube: CVE-2024-35195
Remediation and exploitation details
This chain involves the following actors
This following systems are involved
Attack entry point
Remediation actions
Exploitation actions
Related Content
NOTE: The following related content has not been vetted and may be unsafe.
- https://github.com/psf/requests/security/advisories/GHSA-9wx4-h78v-vm56
- https://github.com/psf/requests/pull/6655
- https://github.com/psf/requests/commit/a58d7f2ffb4d00b46dca2d70a3932a0b37e22fac
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IYLSNK5TL46Q6XPRVMHVWS63MVJQOK4Q/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N7WP6EYDSUOCOJYHDK5NX43PYZ4SNHGZ/