Описание
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support |
| devel | not-affected | |
| esm-apps/bionic | released | 9.0.1-2.3~ubuntu1.18.04.8+esm2 |
| esm-apps/focal | not-affected | |
| esm-apps/jammy | not-affected | |
| esm-apps/noble | not-affected | |
| esm-apps/xenial | released | 8.1.1-2ubuntu0.6+esm6 |
| esm-infra-legacy/trusty | needed | |
| focal | not-affected | |
| jammy | not-affected |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support |
| devel | not-affected | |
| esm-infra-legacy/trusty | needed | |
| esm-infra/bionic | released | 1.22-1ubuntu0.18.04.2+esm1 |
| esm-infra/focal | not-affected | 1.25.8-2ubuntu0.2 |
| esm-infra/xenial | released | 1.13.1-2ubuntu0.16.04.4+esm1 |
| focal | not-affected | 1.25.8-2ubuntu0.2 |
| jammy | not-affected | |
| lunar | not-affected | |
| mantic | not-affected |
Показывать по
Ссылки на источники
6.1 Medium
CVSS3
Связанные уязвимости
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
urllib3 before 1.24.2 does not remove the authorization HTTP header wh ...
6.1 Medium
CVSS3