Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-20060

Опубликовано: 11 дек. 2018
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5
CVSS3: 9.8

Описание

urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.

РелизСтатусПримечание
bionic

released

1.22-1ubuntu0.18.04.1
cosmic

released

1.22-1ubuntu0.18.10.1
devel

not-affected

1.24-1
disco

not-affected

1.24-1
eoan

not-affected

1.24-1
esm-infra-legacy/trusty

needed

esm-infra/bionic

released

1.22-1ubuntu0.18.04.1
esm-infra/focal

not-affected

1.24-1
esm-infra/xenial

released

1.13.1-2ubuntu0.16.04.3
focal

not-affected

1.24-1

Показывать по

EPSS

Процентиль: 62%
0.00434
Низкий

5 Medium

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
больше 7 лет назад

urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.

CVSS3: 9.8
nvd
почти 7 лет назад

urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.

CVSS3: 9.8
debian
почти 7 лет назад

urllib3 before version 1.23 does not remove the Authorization HTTP hea ...

CVSS3: 9.8
github
почти 7 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in urllib3

CVSS3: 9.8
fstec
больше 6 лет назад

Уязвимость модуля urllib3 интерпретатора языка программирования Python, связанная с ошибками управления регистрационными данными, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 62%
0.00434
Низкий

5 Medium

CVSS2

9.8 Critical

CVSS3