Sensitive information sent insecurely In python-urllib3
Description
Exposure of Sensitive Information to an Unauthorized Actor in urllib3 urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 14 | 1.24-1 | ||
debian 13 | 1.24-1 | ||
pypi | 1.23 | ||
debian 11 | 1.24-1 | ||
debian 12 | 1.24-1 | ||
rpm rhel7 | 0:15.1.0-4.el7_8 | ||
rpm rhel7 | 0:1.10.2-7.el7 | ||
rpm rhel7 | 0:9.0.3-7.el7_8 | ||
rpm rhel8 | 0:9.0.3-16.el8 | ||
rpm rhel6 | - | - |
Aliases
1. 2. 3. 4. 5. 6. 7. 8.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15.