CVE-2018-20060
published 2018-12-11CVE-2018-20060: urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port…
PriorityP349critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.49%
90.4th percentile
urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python-urllib3 | < python-urllib3 1.24-1 (bookworm) | python-urllib3 1.24-1 (bookworm) |
| debian | python-urllib3 | < python-urllib3 1.25.6-4 (bookworm) | python-urllib3 1.25.6-4 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_python-virtualenv_20.26.6-1_on_cbl_mariner_2.0 | — | — |
| python | urllib3 | < 1.24.2 | 1.24.2 |
| python | urllib3 | < 1.23 | 1.23 |
| urllib3 | urllib3 | >= 0 < 1.24.2 | 1.24.2 |
| urllib3 | urllib3 | >= 0 < 1.23 | 1.23 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_msrc6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
urllib3: urllib3 does not remove the authorization HTTP header when following a cross-origin redirect
vendor_redhat·2023-10-15·CVSS 9.8
CVE-2018-25091 [CRITICAL] CWE-200 urllib3: urllib3 does not remove the authorization HTTP header when following a cross-origin redirect
urllib3: urllib3 does not remove the authorization HTTP header when following a cross-origin redirect
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
A flaw was found in the urllib3 package. Affected versions of this package are vulnerable to information exposure through sent data when the authorization HTTP header is not removed during a cross-origin redirect. An attacker can expose credentials in the authorization header to unintended hosts or transmit
Microsoft
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in t
vendor_msrc·2023-10-10·CVSS 6.1
CVE-2018-25091 [CRITICAL] CWE-601 urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in t
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transp
Ubuntu
urllib3 vulnerabilities
vendor_ubuntu·2019-05-21·CVSS 9.8
CVE-2018-20060 [CRITICAL] urllib3 vulnerabilities
Title: urllib3 vulnerabilities
Summary: Several security issues were fixed in urllib3.
It was discovered that urllib3 incorrectly removed Authorization HTTP
headers when handled cross-origin redirects. This could result in
credentials being sent to unintended hosts. This issue only affected Ubuntu
16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-20060)
It was discovered that urllib3 incorrectly stripped certain characters from
requests. A remote attacker could use this issue to perform CRLF injection.
(CVE-2019-11236)
It was discovered that urllib3 incorrectly handled situations where a
desired set of CA certificates were specified. This could result in
certificates being accepted by the default CA certificates contrary to
expectations. This issue only affected Ubuntu 18.04 LTS,
Red Hat
python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure
vendor_redhat·2018-03-26·CVSS 9.8
CVE-2018-20060 [CRITICAL] CWE-522 python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure
python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure
urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.
Statement: Red Hat Satellite 6.2 is on Maintenance Support 2 phase, hence only selected critical and important issues will be fixed. Please refer to Red Hat Satellite Product Life Cycle page for more information.
In Red Hat OpenStack Platform 13, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP py
Debian
CVE-2018-20060: python-urllib3 - urllib3 before version 1.23 does not remove the Authorization HTTP header when f...
vendor_debian·2018·CVSS 9.8
CVE-2018-20060 [CRITICAL] CVE-2018-20060: python-urllib3 - urllib3 before version 1.23 does not remove the Authorization HTTP header when f...
urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.
Scope: local
bookworm: resolved (fixed in 1.24-1)
bullseye: resolved (fixed in 1.24-1)
forky: resolved (fixed in 1.24-1)
sid: resolved (fixed in 1.24-1)
trixie: resolved (fixed in 1.24-1)
Debian
CVE-2018-25091: python-urllib3 - urllib3 before 1.24.2 does not remove the authorization HTTP header when followi...
vendor_debian·2018·CVSS 9.8
CVE-2018-25091 [CRITICAL] CVE-2018-25091: python-urllib3 - urllib3 before 1.24.2 does not remove the authorization HTTP header when followi...
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
Scope: local
bookworm: resolved (fixed in 1.25.6-4)
bullseye: resolved (fixed in 1.25.6-4)
forky: resolved (fixed in 1.25.6-4)
sid: resolved (fixed in 1.25.6-4)
trixie: resolved (fixed in 1.25.6-4)
GHSA
Authorization Header forwarded on redirect
ghsa·2023-10-15·CVSS 9.8
CVE-2018-25091 [CRITICAL] CWE-200 Authorization Header forwarded on redirect
Authorization Header forwarded on redirect
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
OSV
CVE-2018-25091: urllib3 before 1
osv·2023-10-15·CVSS 9.8
CVE-2018-25091 [CRITICAL] CVE-2018-25091: urllib3 before 1
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
OSV
Authorization Header forwarded on redirect
osv·2023-10-15·CVSS 9.8
CVE-2018-25091 [CRITICAL] Authorization Header forwarded on redirect
Authorization Header forwarded on redirect
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
OSV
python-urllib3 vulnerabilities
osv·2019-05-21·CVSS 9.8
CVE-2018-20060 [CRITICAL] python-urllib3 vulnerabilities
python-urllib3 vulnerabilities
It was discovered that urllib3 incorrectly removed Authorization HTTP
headers when handled cross-origin redirects. This could result in
credentials being sent to unintended hosts. This issue only affected Ubuntu
16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-20060)
It was discovered that urllib3 incorrectly stripped certain characters from
requests. A remote attacker could use this issue to perform CRLF injection.
(CVE-2019-11236)
It was discovered that urllib3 incorrectly handled situations where a
desired set of CA certificates were specified. This could result in
certificates being accepted by the default CA certificates contrary to
expectations. This issue only affected Ubuntu 18.04 LTS, Ubuntu 18.10, and
Ubuntu 19.04. (CVE-2019-11324)
OSV
Exposure of Sensitive Information to an Unauthorized Actor in urllib3
osv·2018-12-12
CVE-2018-20060 [CRITICAL] Exposure of Sensitive Information to an Unauthorized Actor in urllib3
Exposure of Sensitive Information to an Unauthorized Actor in urllib3
urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in urllib3
ghsa·2018-12-12
CVE-2018-20060 [CRITICAL] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in urllib3
Exposure of Sensitive Information to an Unauthorized Actor in urllib3
urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.
OSV
CVE-2018-20060: urllib3 before version 1
osv·2018-12-11·CVSS 9.8
CVE-2018-20060 [CRITICAL] CVE-2018-20060: urllib3 before version 1
urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-25091 urllib3: urllib3 does not remove the authorization HTTP header when following a cross-origin redirect
bugzilla·2023-10-16·CVSS 9.8
CVE-2018-25091 [CRITICAL] CVE-2018-25091 urllib3: urllib3 does not remove the authorization HTTP header when following a cross-origin redirect
CVE-2018-25091 urllib3: urllib3 does not remove the authorization HTTP header when following a cross-origin redirect
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
https://github.com/urllib3/urllib3/compare/1.24.1...1.24.2
https://github.com/urllib3/urllib3/issues/1510
https://github.com/urllib3/urllib3/commit/adb358f8e06865406d1f05e581a16cbea2136fbc
Discussion:
Created ansible-lint tracking bugs for this issue:
Affects: fedora-all [bug 2246497]
Cre
Bugzilla
CVE-2018-20060 python-virtualenv: python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [epel-6]
bugzilla·2019-11-29·CVSS 9.8
CVE-2018-20060 [CRITICAL] CVE-2018-20060 python-virtualenv: python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [epel-6]
CVE-2018-20060 python-virtualenv: python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commi
Bugzilla
CVE-2018-20060 python-virtualenv: python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [fedora-30]
bugzilla·2019-11-29·CVSS 9.8
CVE-2018-20060 [CRITICAL] CVE-2018-20060 python-virtualenv: python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [fedora-30]
CVE-2018-20060 python-virtualenv: python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [fedora-30]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-30.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg
Bugzilla
CVE-2018-20060 python3-virtualenv: python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [epel-7]
bugzilla·2019-11-29·CVSS 9.8
CVE-2018-20060 [CRITICAL] CVE-2018-20060 python3-virtualenv: python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [epel-7]
CVE-2018-20060 python3-virtualenv: python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg comm
Bugzilla
CVE-2018-20060 python-pip: python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [epel-6]
bugzilla·2019-11-20·CVSS 9.8
CVE-2018-20060 [CRITICAL] CVE-2018-20060 python-pip: python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [epel-6]
CVE-2018-20060 python-pip: python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messa
Bugzilla
CVE-2018-20060 python-pip-epel: python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [epel-7]
bugzilla·2019-11-20·CVSS 9.8
CVE-2018-20060 [CRITICAL] CVE-2018-20060 python-pip-epel: python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [epel-7]
CVE-2018-20060 python-pip-epel: python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
Bugzilla
CVE-2018-20060 python-pip: python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [fedora-29]
bugzilla·2019-11-20·CVSS 9.8
CVE-2018-20060 [CRITICAL] CVE-2018-20060 python-pip: python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [fedora-29]
CVE-2018-20060 python-pip: python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [fedora-29]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-29.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
Bugzilla
CVE-2018-20060 python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [fedora-27]
bugzilla·2018-11-13·CVSS 9.8
CVE-2018-20060 [CRITICAL] CVE-2018-20060 python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [fedora-27]
CVE-2018-20060 python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [fedora-27]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-27.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2018-20060 python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [fedora-28]
bugzilla·2018-11-13·CVSS 9.8
CVE-2018-20060 [CRITICAL] CVE-2018-20060 python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [fedora-28]
CVE-2018-20060 python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [fedora-28]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-28.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2018-20060 python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [epel-all]
bugzilla·2018-11-13·CVSS 9.8
CVE-2018-20060 [CRITICAL] CVE-2018-20060 python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [epel-all]
CVE-2018-20060 python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOT
Bugzilla
CVE-2018-20060 python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure
bugzilla·2018-11-13·CVSS 9.8
CVE-2018-20060 [CRITICAL] CVE-2018-20060 python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure
CVE-2018-20060 python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure
python-urllib3 before version 1.23 does not remove the 'Authorization' HTTP header when following a cross-origin redirect. This can allow for credentials in the 'Authorization' header to be exposed as they are transmitted in plaintext.
Upstream Issues:
https://github.com/urllib3/urllib3/issues/1316
https://github.com/urllib3/urllib3/pull/1346
Discussion:
Created python-urllib3 tracking bugs for this issue:
Affects: epel-all [bug 1649156]
Affects: fedora-27 [bug 1649154]
Affects: fedora-28 [bug 1649155]
Affects: openstack-rdo [bug 1649157]
---
Upstream patch commits:
https://github.com/urllib3/urllib3/commit/3d7f98b07b6e6e04c2e89cdf5afb18024a2d804c
https://github.co
Bugzilla
CVE-2018-20060 python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [openstack-rdo]
bugzilla·2018-11-13·CVSS 9.8
CVE-2018-20060 [CRITICAL] CVE-2018-20060 python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [openstack-rdo]
CVE-2018-20060 python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit mes
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00039.htmlhttps://access.redhat.com/errata/RHSA-2019:2272https://bugzilla.redhat.com/show_bug.cgi?id=1649153https://github.com/urllib3/urllib3/blob/master/CHANGES.rsthttps://github.com/urllib3/urllib3/issues/1316https://github.com/urllib3/urllib3/pull/1346https://lists.debian.org/debian-lts-announce/2021/06/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5SJERZEJDSUYQP7BNBXMBHRHGY26HRZD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BXLAXHM3Z6DUCXZ7ZXZ2EAYJXWDCZFCT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWP36YW3KSVLXDBY3QJKDYEPCIMN3VQZ/https://usn.ubuntu.com/3990-1/http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00039.htmlhttps://access.redhat.com/errata/RHSA-2019:2272https://bugzilla.redhat.com/show_bug.cgi?id=1649153https://github.com/urllib3/urllib3/blob/master/CHANGES.rsthttps://github.com/urllib3/urllib3/issues/1316https://github.com/urllib3/urllib3/pull/1346https://lists.debian.org/debian-lts-announce/2021/06/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5SJERZEJDSUYQP7BNBXMBHRHGY26HRZD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BXLAXHM3Z6DUCXZ7ZXZ2EAYJXWDCZFCT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWP36YW3KSVLXDBY3QJKDYEPCIMN3VQZ/https://security.netapp.com/advisory/ntap-20241227-0010/https://usn.ubuntu.com/3990-1/
2018-12-11
Published