PT-2021-18240 · Pypi · Requests

Whyisjake

+1

·

Published

2021-04-27

·

Updated

2021-05-07

·

CVE-2021-29476

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Requests versions 1.6.0 through 1.7.0
Description: The issue concerns the mishandling of deserialization in FilteredIterator. This allows for the unserialization of untrusted data.
Recommendations: For versions 1.6.0, 1.6.1, and 1.7.0, update to version 1.8.0.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-29476
GHSA-52QP-JPQ7-6C54

Affected Products

Requests