Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-www2-v7xj-xrc6

Опубликовано: 12 дек. 2018
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Exposure of Sensitive Information to an Unauthorized Actor in urllib3

urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.

Пакеты

Наименование

urllib3

pip
Затронутые версииВерсия исправления

< 1.23

1.23

EPSS

Процентиль: 64%
0.00481
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.

CVSS3: 5.3
redhat
около 7 лет назад

urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.

CVSS3: 9.8
nvd
больше 6 лет назад

urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.

CVSS3: 9.8
debian
больше 6 лет назад

urllib3 before version 1.23 does not remove the Authorization HTTP hea ...

CVSS3: 9.8
fstec
около 6 лет назад

Уязвимость модуля urllib3 интерпретатора языка программирования Python, связанная с ошибками управления регистрационными данными, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 64%
0.00481
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-200