CVE-2024-35195: Requests `Session` object does not verify requests after making first request with verify=False
Published May 20, 2024
·Updated
Requests `Session` object does not verify requests after making first request with verify=False
Affected Software
17 affected componentsFixes available
pip/requests<2.32.0
2.32.0
F5 Traffix SDC=5.1.0
5.2.0
Microsoft azl3 tensorflow 2.16.1-8
Microsoft azl3 tensorflow 2.16.1-9
Microsoft cbl2 python-requests 2.27.1-7
Microsoft azl3 python-requests 2.31.0-2
redhat/requests<2.32.0
2.32.0
IBM Cognos Analytics<=11.2.0
IBM Cognos Analytics<=12.0
IBM Cognos Transformer<=12.0
IBM Cognos Transformer<=11.2.4
IBM Cognos Transformer<=12.1.0
IBM Cognos Analytics<=11.2.0
IBM Cognos Analytics<=12.1.0
IBM Cognos Analytics<=12.0
IBM Cognos Transformer<=11.2.4
IBM Cognos Transformer<=12.1.0
Event History
May 20, 2024
CVE Published
via MITRE·08:14 PM
Data Sourced
via MITRE·08:14 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·08:15 PM
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
May 21, 2024
Data Sourced
via Red Hat·10:25 AM
DescriptionSeverityAffected Software
May 23, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Sep 20, 2024
Advisory Published
via F5·09:27 PM
May 26, 2026
Data Sourced
via IBM·05:05 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-35195?
CVE-2024-35195 has been categorized as a moderate severity vulnerability.
2
How do I fix CVE-2024-35195?
To fix CVE-2024-35195, upgrade the requests library to version 2.32.0 or later.
3
What versions of Requests are affected by CVE-2024-35195?
CVE-2024-35195 affects all versions of the Requests library prior to 2.32.0.
4
What is the main issue described in CVE-2024-35195?
The main issue in CVE-2024-35195 is that disabling SSL certificate verification in a Requests session affects all subsequent requests to the same host.
5
Is CVE-2024-35195 applicable to F5 Traffix SDC products?
Yes, CVE-2024-35195 is applicable to F5 Traffix SDC version 5.1.0 and earlier.