cbcvebase.
CVE-2018-20060
published 2018-12-11

CVE-2018-20060: urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port…

PriorityP349critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.49%
90.4th percentile
urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianpython-urllib3< python-urllib3 1.24-1 (bookworm)python-urllib3 1.24-1 (bookworm)
debianpython-urllib3< python-urllib3 1.25.6-4 (bookworm)python-urllib3 1.25.6-4 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_python-virtualenv_20.26.6-1_on_cbl_mariner_2.0
pythonurllib3< 1.24.21.24.2
pythonurllib3< 1.231.23
urllib3urllib3>= 0 < 1.24.21.24.2
urllib3urllib3>= 0 < 1.231.23

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_msrc6.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.