Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Update request to 2.20.0 (elastic#8808) (elastic#8821)
The Requests package through 2.19.1 before 2018-09-14 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network. https://nvd.nist.gov/vuln/detail/CVE-2018-18074 (cherry picked from commit 34248d9)
- Loading branch information