Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependency requests to >=2.31.0, <2.32 [security] - autoclosed #276

Closed
wants to merge 1 commit into from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented May 23, 2023

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
requests (source, changelog) >=2.28, <2.31 -> >=2.31.0, <2.32 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2023-32681

Impact

Since Requests v2.3.0, Requests has been vulnerable to potentially leaking Proxy-Authorization headers to destination servers, specifically during redirects to an HTTPS origin. This is a product of how rebuild_proxies is used to recompute and reattach the Proxy-Authorization header to requests when redirected. Note this behavior has only been observed to affect proxied requests when credentials are supplied in the URL user information component (e.g. https://username:password@proxy:8080).

Current vulnerable behavior(s):

  1. HTTP → HTTPS: leak
  2. HTTPS → HTTP: no leak
  3. HTTPS → HTTPS: leak
  4. HTTP → HTTP: no leak

For HTTP connections sent through the proxy, the proxy will identify the header in the request itself and remove it prior to forwarding to the destination server. However when sent over HTTPS, the Proxy-Authorization header must be sent in the CONNECT request as the proxy has no visibility into further tunneled requests. This results in Requests forwarding the header to the destination server unintentionally, allowing a malicious actor to potentially exfiltrate those credentials.

The reason this currently works for HTTPS connections in Requests is the Proxy-Authorization header is also handled by urllib3 with our usage of the ProxyManager in adapters.py with proxy_manager_for. This will compute the required proxy headers in proxy_headers and pass them to the Proxy Manager, avoiding attaching them directly to the Request object. This will be our preferred option going forward for default usage.

Patches

Starting in Requests v2.31.0, Requests will no longer attach this header to redirects with an HTTPS destination. This should have no negative impacts on the default behavior of the library as the proxy credentials are already properly being handled by urllib3's ProxyManager.

For users with custom adapters, this may be potentially breaking if you were already working around this behavior. The previous functionality of rebuild_proxies doesn't make sense in any case, so we would encourage any users impacted to migrate any handling of Proxy-Authorization directly into their custom adapter.

Workarounds

For users who are not able to update Requests immediately, there is one potential workaround.

You may disable redirects by setting allow_redirects to False on all calls through Requests top-level APIs. Note that if you're currently relying on redirect behaviors, you will need to capture the 3xx response codes and ensure a new request is made to the redirect destination.

import requests
r = requests.get('http://github.com/', allow_redirects=False)

Credits

This vulnerability was discovered and disclosed by the following individuals.

Dennis Brinkrolf, Haxolot (https://haxolot.com/)
Tobias Funke, (tobiasfunke93@​gmail.com)


Release Notes

psf/requests (requests)

v2.31.0

Compare Source

Security

  • Versions of Requests between v2.3.0 and v2.30.0 are vulnerable to potential
    forwarding of Proxy-Authorization headers to destination servers when
    following HTTPS redirects.

    When proxies are defined with user info (https://user:pass@proxy:8080), Requests
    will construct a Proxy-Authorization header that is attached to the request to
    authenticate with the proxy.

    In cases where Requests receives a redirect response, it previously reattached
    the Proxy-Authorization header incorrectly, resulting in the value being
    sent through the tunneled connection to the destination server. Users who rely on
    defining their proxy credentials in the URL are strongly encouraged to upgrade
    to Requests 2.31.0+ to prevent unintentional leakage and rotate their proxy
    credentials once the change has been fully deployed.

    Users who do not use a proxy or do not supply their proxy credentials through
    the user information portion of their proxy URL are not subject to this
    vulnerability.

    Full details can be read in our Github Security Advisory
    and CVE-2023-32681.

v2.30.0

Compare Source

Dependencies

v2.29.0

Compare Source

Improvements

  • Requests now defers chunked requests to the urllib3 implementation to improve
    standardization. (#​6226)
  • Requests relaxes header component requirements to support bytes/str subclasses. (#​6356)

v2.28.2

Compare Source

Dependencies

  • Requests now supports charset_normalizer 3.x. (#​6261)

Bugfixes

  • Updated MissingSchema exception to suggest https scheme rather than http. (#​6188)

v2.28.1

Compare Source

Improvements

  • Speed optimization in iter_content with transition to yield from. (#​6170)

Dependencies

  • Added support for chardet 5.0.0 (#​6179)
  • Added support for charset-normalizer 2.1.0 (#​6169)

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31.0, <2.32 [security] chore(deps): update dependency requests to >=2.31, <2.32 [security] May 26, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 32f8a15 to 1bb8b10 Compare May 26, 2023 06:56
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31, <2.32 [security] chore(deps): update dependency requests to >=2.31.0, <2.32 [security] May 26, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 1bb8b10 to a59898a Compare May 26, 2023 11:19
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31.0, <2.32 [security] chore(deps): update dependency requests to >=2.31, <2.32 [security] May 28, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from a59898a to b5e81fa Compare May 28, 2023 11:02
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31, <2.32 [security] chore(deps): update dependency requests to >=2.31.0, <2.32 [security] May 28, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from b5e81fa to 1f740b3 Compare May 28, 2023 13:34
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31.0, <2.32 [security] chore(deps): update dependency requests to >=2.31, <2.32 [security] May 30, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 1f740b3 to 80b5df5 Compare May 30, 2023 04:09
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31, <2.32 [security] chore(deps): update dependency requests to >=2.31.0, <2.32 [security] May 30, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 80b5df5 to c209023 Compare May 30, 2023 04:16
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31.0, <2.32 [security] chore(deps): update dependency requests to >=2.31, <2.32 [security] May 31, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from c209023 to 0fab5cf Compare May 31, 2023 09:50
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31, <2.32 [security] chore(deps): update dependency requests to >=2.31.0, <2.32 [security] May 31, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 0fab5cf to f6edbff Compare May 31, 2023 09:51
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31.0, <2.32 [security] chore(deps): update dependency requests to >=2.31, <2.32 [security] May 31, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from f6edbff to c4f1740 Compare May 31, 2023 09:59
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31, <2.32 [security] chore(deps): update dependency requests to >=2.31.0, <2.32 [security] May 31, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from c4f1740 to e65e397 Compare May 31, 2023 10:01
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31.0, <2.32 [security] chore(deps): update dependency requests to >=2.31, <2.32 [security] Jun 6, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from e65e397 to 5bbba5b Compare June 6, 2023 07:01
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31, <2.32 [security] chore(deps): update dependency requests to >=2.31.0, <2.32 [security] Jun 6, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 5bbba5b to 11b52b3 Compare June 6, 2023 07:03
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31.0, <2.32 [security] chore(deps): update dependency requests to >=2.31, <2.32 [security] Jun 7, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 11b52b3 to a3d0fc8 Compare June 7, 2023 09:32
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31, <2.32 [security] chore(deps): update dependency requests to >=2.31.0, <2.32 [security] Jun 7, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from a3d0fc8 to 5186924 Compare June 7, 2023 09:34
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31.0, <2.32 [security] chore(deps): update dependency requests to >=2.31, <2.32 [security] Jun 18, 2023
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 5186924 to 11557e5 Compare June 18, 2023 09:11
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from bc88a29 to 9f2c9ba Compare May 3, 2024 00:15
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31, <2.32 [security] chore(deps): update dependency requests to >=2.31.0, <2.32 [security] May 3, 2024
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31.0, <2.32 [security] chore(deps): update dependency requests to >=2.31, <2.32 [security] May 3, 2024
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 9f2c9ba to cfc473f Compare May 3, 2024 18:06
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31, <2.32 [security] chore(deps): update dependency requests to >=2.31.0, <2.32 [security] May 3, 2024
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch 2 times, most recently from 952b3a2 to 3dc57f9 Compare May 6, 2024 02:51
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31.0, <2.32 [security] chore(deps): update dependency requests to >=2.31, <2.32 [security] May 6, 2024
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 3dc57f9 to e946ced Compare May 6, 2024 04:03
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31, <2.32 [security] chore(deps): update dependency requests to >=2.31.0, <2.32 [security] May 6, 2024
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from e946ced to 831e8ec Compare May 6, 2024 04:03
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31.0, <2.32 [security] chore(deps): update dependency requests to >=2.31, <2.32 [security] May 6, 2024
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 831e8ec to 3549d39 Compare May 6, 2024 08:23
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31, <2.32 [security] chore(deps): update dependency requests to >=2.31.0, <2.32 [security] May 6, 2024
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31.0, <2.32 [security] chore(deps): update dependency requests to >=2.31, <2.32 [security] May 7, 2024
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch 2 times, most recently from ec5846b to 130c25a Compare May 7, 2024 19:49
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31, <2.32 [security] chore(deps): update dependency requests to >=2.31.0, <2.32 [security] May 7, 2024
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31.0, <2.32 [security] chore(deps): update dependency requests to >=2.31, <2.32 [security] May 9, 2024
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 130c25a to 744be18 Compare May 9, 2024 11:29
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31, <2.32 [security] chore(deps): update dependency requests to >=2.31.0, <2.32 [security] May 9, 2024
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 744be18 to 32486a7 Compare May 9, 2024 13:50
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31.0, <2.32 [security] chore(deps): update dependency requests to >=2.31, <2.32 [security] May 15, 2024
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 32486a7 to 3b43c2d Compare May 15, 2024 11:32
@renovate renovate bot force-pushed the renovate/pypi-requests-vulnerability branch from 3b43c2d to b541c93 Compare May 15, 2024 21:31
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31, <2.32 [security] chore(deps): update dependency requests to >=2.31.0, <2.32 [security] May 15, 2024
@renovate renovate bot changed the title chore(deps): update dependency requests to >=2.31.0, <2.32 [security] chore(deps): update dependency requests to >=2.31.0, <2.32 [security] - autoclosed May 21, 2024
@renovate renovate bot closed this May 21, 2024
@renovate renovate bot deleted the renovate/pypi-requests-vulnerability branch May 21, 2024 19:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants