Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependency requests to v2.32.0 [security] - autoclosed #209

Closed
wants to merge 1 commit into from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented May 23, 2023

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
requests (source, changelog) ==2.28 -> ==2.32.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2023-32681

Impact

Since Requests v2.3.0, Requests has been vulnerable to potentially leaking Proxy-Authorization headers to destination servers, specifically during redirects to an HTTPS origin. This is a product of how rebuild_proxies is used to recompute and reattach the Proxy-Authorization header to requests when redirected. Note this behavior has only been observed to affect proxied requests when credentials are supplied in the URL user information component (e.g. https://username:password@proxy:8080).

Current vulnerable behavior(s):

  1. HTTP → HTTPS: leak
  2. HTTPS → HTTP: no leak
  3. HTTPS → HTTPS: leak
  4. HTTP → HTTP: no leak

For HTTP connections sent through the proxy, the proxy will identify the header in the request itself and remove it prior to forwarding to the destination server. However when sent over HTTPS, the Proxy-Authorization header must be sent in the CONNECT request as the proxy has no visibility into further tunneled requests. This results in Requests forwarding the header to the destination server unintentionally, allowing a malicious actor to potentially exfiltrate those credentials.

The reason this currently works for HTTPS connections in Requests is the Proxy-Authorization header is also handled by urllib3 with our usage of the ProxyManager in adapters.py with proxy_manager_for. This will compute the required proxy headers in proxy_headers and pass them to the Proxy Manager, avoiding attaching them directly to the Request object. This will be our preferred option going forward for default usage.

Patches

Starting in Requests v2.31.0, Requests will no longer attach this header to redirects with an HTTPS destination. This should have no negative impacts on the default behavior of the library as the proxy credentials are already properly being handled by urllib3's ProxyManager.

For users with custom adapters, this may be potentially breaking if you were already working around this behavior. The previous functionality of rebuild_proxies doesn't make sense in any case, so we would encourage any users impacted to migrate any handling of Proxy-Authorization directly into their custom adapter.

Workarounds

For users who are not able to update Requests immediately, there is one potential workaround.

You may disable redirects by setting allow_redirects to False on all calls through Requests top-level APIs. Note that if you're currently relying on redirect behaviors, you will need to capture the 3xx response codes and ensure a new request is made to the redirect destination.

import requests
r = requests.get('http://github.com/', allow_redirects=False)

Credits

This vulnerability was discovered and disclosed by the following individuals.

Dennis Brinkrolf, Haxolot (https://haxolot.com/)
Tobias Funke, (tobiasfunke93@​gmail.com)

CVE-2024-35195

When making requests through a Requests Session, if the first request is made with verify=False to disable cert verification, all subsequent requests to the same origin will continue to ignore cert verification regardless of changes to the value of verify. This behavior will continue for the lifecycle of the connection in the connection pool.

Remediation

Any of these options can be used to remediate the current issue, we highly recommend upgrading as the preferred mitigation.

  • Upgrade to requests>=2.32.0.
  • For requests<2.32.0, avoid setting verify=False for the first request to a host while using a Requests Session.
  • For requests<2.32.0, call close() on Session objects to clear existing connections if verify=False is used.

Related Links


Release Notes

psf/requests (requests)

v2.32.0

Compare Source

Security

  • Fixed an issue where setting verify=False on the first request from a
    Session will cause subsequent requests to the same origin to also ignore
    cert verification, regardless of the value of verify.
    (GHSA-9wx4-h78v-vm56)

Improvements

  • verify=True now reuses a global SSLContext which should improve
    request time variance between first and subsequent requests. It should
    also minimize certificate load time on Windows systems when using a Python
    version built with OpenSSL 3.x. (#​6667)
  • Requests now supports optional use of character detection
    (chardet or charset_normalizer) when repackaged or vendored.
    This enables pip and other projects to minimize their vendoring
    surface area. The Response.text() and apparent_encoding APIs
    will default to utf-8 if neither library is present. (#​6702)

Bugfixes

  • Fixed bug in length detection where emoji length was incorrectly
    calculated in the request content-length. (#​6589)
  • Fixed deserialization bug in JSONDecodeError. (#​6629)
  • Fixed bug where an extra leading / (path separator) could lead
    urllib3 to unnecessarily reparse the request URI. (#​6644)

Deprecations

  • Requests has officially added support for CPython 3.12 (#​6503)
  • Requests has officially added support for PyPy 3.9 and 3.10 (#​6641)
  • Requests has officially dropped support for CPython 3.7 (#​6642)
  • Requests has officially dropped support for PyPy 3.7 and 3.8 (#​6641)

Documentation

  • Various typo fixes and doc improvements.

Packaging

  • Requests has started adopting some modern packaging practices.
    The source files for the projects (formerly requests) is now located
    in src/requests in the Requests sdist. (#​6506)
  • Starting in Requests 2.33.0, Requests will migrate to a PEP 517 build system
    using hatchling. This should not impact the average user, but extremely old
    versions of packaging utilities may have issues with the new packaging format.

v2.31.0

Compare Source

Security

  • Versions of Requests between v2.3.0 and v2.30.0 are vulnerable to potential
    forwarding of Proxy-Authorization headers to destination servers when
    following HTTPS redirects.

    When proxies are defined with user info (https://user:pass@proxy:8080), Requests
    will construct a Proxy-Authorization header that is attached to the request to
    authenticate with the proxy.

    In cases where Requests receives a redirect response, it previously reattached
    the Proxy-Authorization header incorrectly, resulting in the value being
    sent through the tunneled connection to the destination server. Users who rely on
    defining their proxy credentials in the URL are strongly encouraged to upgrade
    to Requests 2.31.0+ to prevent unintentional leakage and rotate their proxy
    credentials once the change has been fully deployed.

    Users who do not use a proxy or do not supply their proxy credentials through
    the user information portion of their proxy URL are not subject to this
    vulnerability.

    Full details can be read in our Github Security Advisory
    and CVE-2023-32681.

v2.30.0

Compare Source

Dependencies

v2.29.0

Compare Source

Improvements

  • Requests now defers chunked requests to the urllib3 implementation to improve
    standardization. (#​6226)
  • Requests relaxes header component requirements to support bytes/str subclasses. (#​6356)

v2.28.2

Compare Source

Dependencies

  • Requests now supports charset_normalizer 3.x. (#​6261)

Bugfixes

  • Updated MissingSchema exception to suggest https scheme rather than http. (#​6188)

v2.28.1

Compare Source

Improvements

  • Speed optimization in iter_content with transition to yield from. (#​6170)

Dependencies

  • Added support for chardet 5.0.0 (#​6179)
  • Added support for charset-normalizer 2.1.0 (#​6169)

Configuration

📅 Schedule: Branch creation - "" in timezone Europe/Paris, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 6c7699f to b8f5310 Compare May 26, 2023 06:21
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.31.0 [security] chore(deps): update dependency requests to v2.28.2 [security] May 26, 2023
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.28.2 [security] chore(deps): update dependency requests to v2.31.0 [security] May 26, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from b8f5310 to eea7c8f Compare May 26, 2023 10:55
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.31.0 [security] chore(deps): update dependency requests to v2.28.2 [security] May 26, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from eea7c8f to a29d0b3 Compare May 26, 2023 15:15
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.28.2 [security] chore(deps): update dependency requests to v2.31.0 [security] May 26, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from a29d0b3 to 81802cf Compare May 26, 2023 19:30
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.31.0 [security] chore(deps): update dependency requests to v2.28.2 [security] May 28, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 81802cf to 1e37802 Compare May 28, 2023 12:19
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.28.2 [security] chore(deps): update dependency requests to v2.31.0 [security] May 28, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch 2 times, most recently from ba61e01 to cfe12c0 Compare June 4, 2023 13:06
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.31.0 [security] chore(deps): update dependency requests to v2.28.2 [security] Jun 4, 2023
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.28.2 [security] chore(deps): update dependency requests to v2.31.0 [security] Jun 4, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from cfe12c0 to c116877 Compare June 4, 2023 17:07
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.31.0 [security] chore(deps): update dependency requests to v2.28.2 [security] Jun 13, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from c116877 to 716165d Compare June 13, 2023 14:00
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.28.2 [security] chore(deps): update dependency requests to v2.31.0 [security] Jun 13, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 716165d to 2cfcc0a Compare June 13, 2023 18:10
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.31.0 [security] chore(deps): update dependency requests to v2.28.2 [security] Jun 18, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 2cfcc0a to 817a675 Compare June 18, 2023 06:36
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.28.2 [security] chore(deps): update dependency requests to v2.31.0 [security] Jun 18, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 817a675 to 278ce01 Compare June 18, 2023 10:41
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.31.0 [security] chore(deps): update dependency requests to v2.28.2 [security] Jun 19, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 278ce01 to f3eb181 Compare June 19, 2023 07:12
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.28.2 [security] chore(deps): update dependency requests to v2.31.0 [security] Jun 19, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from f3eb181 to fd4f076 Compare June 19, 2023 12:19
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.31.0 [security] chore(deps): update dependency requests to v2.28.2 [security] Jun 21, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch 2 times, most recently from 284d9b3 to 922eefa Compare April 24, 2024 08:29
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.28.2 [security] chore(deps): update dependency requests to v2.31.0 [security] Apr 24, 2024
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch 2 times, most recently from ffaf8df to 0a62681 Compare April 25, 2024 09:26
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.31.0 [security] chore(deps): update dependency requests to v2.28.2 [security] Apr 25, 2024
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 0a62681 to d329c61 Compare April 25, 2024 13:16
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.28.2 [security] chore(deps): update dependency requests to v2.31.0 [security] Apr 25, 2024
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from d329c61 to e3d6ed6 Compare May 1, 2024 09:49
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.31.0 [security] chore(deps): update dependency requests to v2.28.2 [security] May 1, 2024
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from e3d6ed6 to 6b2554f Compare May 1, 2024 12:21
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.28.2 [security] chore(deps): update dependency requests to v2.31.0 [security] May 1, 2024
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 6b2554f to 0bac502 Compare May 9, 2024 08:50
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.31.0 [security] chore(deps): update dependency requests to v2.28.2 [security] May 9, 2024
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 0bac502 to bda816f Compare May 9, 2024 10:05
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.28.2 [security] chore(deps): update dependency requests to v2.31.0 [security] May 9, 2024
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from bda816f to 067339f Compare May 15, 2024 10:40
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.31.0 [security] chore(deps): update dependency requests to v2.28.2 [security] May 15, 2024
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 067339f to 43b9f22 Compare May 15, 2024 21:36
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.28.2 [security] chore(deps): update dependency requests to v2.31.0 [security] May 15, 2024
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 43b9f22 to 534e7d1 Compare May 17, 2024 16:36
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.31.0 [security] chore(deps): update dependency requests to v2.28.2 [security] May 17, 2024
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 534e7d1 to 0ff740e Compare May 17, 2024 16:37
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.28.2 [security] chore(deps): update dependency requests to v2.31.0 [security] May 17, 2024
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 0ff740e to 00b96ce Compare May 21, 2024 15:46
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.31.0 [security] chore(deps): update dependency requests to v2.32.0 [security] May 21, 2024
@renovate renovate bot changed the title chore(deps): update dependency requests to v2.32.0 [security] chore(deps): update dependency requests to v2.32.0 [security] - autoclosed May 22, 2024
@renovate renovate bot closed this May 22, 2024
@renovate renovate bot deleted the renovate/pypi-requests-vulnerability branch May 22, 2024 02:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

0 participants