CVE-2018-25091
published 2023-10-15CVE-2018-25091: urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.51%
40.2th percentile
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python-urllib3 | < python-urllib3 1.25.6-4 (bookworm) | python-urllib3 1.25.6-4 (bookworm) |
| msrc | cbl2_python-virtualenv_20.26.6-1_on_cbl_mariner_2.0 | — | — |
| python | urllib3 | < 1.24.2 | 1.24.2 |
| urllib3 | urllib3 | >= 0 < 1.24.2 | 1.24.2 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_msrc6.1MEDIUM
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
pip vulnerabilities
vendor_ubuntu·2023-11-15·CVSS 6.1
CVE-2023-45803 [MEDIUM] pip vulnerabilities
Title: pip vulnerabilities
Summary: Several security issues were fixed in pip.
USN-6473-1 fixed vulnerabilities in urllib3. This update provides the
corresponding updates for the urllib3 module bundled into pip.
Original advisory details:
It was discovered that urllib3 didn't strip HTTP Authorization header
on cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-25091)
It was discovered that urllib3 didn't strip HTTP Cookie header on
cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. (CVE-2023-43804)
It was discovered that urllib3 didn't strip HTTP body on status code
303 redirects under certain circumstanc
Ubuntu
urllib3 vulnerabilities
vendor_ubuntu·2023-11-07·CVSS 6.1
CVE-2023-45803 [MEDIUM] urllib3 vulnerabilities
Title: urllib3 vulnerabilities
Summary: Several security issues were fixed in urllib3.
It was discovered that urllib3 didn't strip HTTP Authorization header
on cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-25091)
It was discovered that urllib3 didn't strip HTTP Cookie header on
cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. (CVE-2023-43804)
It was discovered that urllib3 didn't strip HTTP body on status code
303 redirects under certain circumstances. A remote attacker could
possibly use this issue to obtain sensitive information. (CVE-2023-45803)
Instructions: In general, a standard system update
Red Hat
urllib3: urllib3 does not remove the authorization HTTP header when following a cross-origin redirect
vendor_redhat·2023-10-15·CVSS 9.8
CVE-2018-25091 [CRITICAL] CWE-200 urllib3: urllib3 does not remove the authorization HTTP header when following a cross-origin redirect
urllib3: urllib3 does not remove the authorization HTTP header when following a cross-origin redirect
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
A flaw was found in the urllib3 package. Affected versions of this package are vulnerable to information exposure through sent data when the authorization HTTP header is not removed during a cross-origin redirect. An attacker can expose credentials in the authorization header to unintended hosts or transmit
Microsoft
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in t
vendor_msrc·2023-10-10·CVSS 6.1
CVE-2018-25091 [CRITICAL] CWE-601 urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in t
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transp
Debian
CVE-2018-25091: python-urllib3 - urllib3 before 1.24.2 does not remove the authorization HTTP header when followi...
vendor_debian·2018·CVSS 9.8
CVE-2018-25091 [CRITICAL] CVE-2018-25091: python-urllib3 - urllib3 before 1.24.2 does not remove the authorization HTTP header when followi...
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
Scope: local
bookworm: resolved (fixed in 1.25.6-4)
bullseye: resolved (fixed in 1.25.6-4)
forky: resolved (fixed in 1.25.6-4)
sid: resolved (fixed in 1.25.6-4)
trixie: resolved (fixed in 1.25.6-4)
OSV
python-pip vulnerabilities
osv·2023-11-15·CVSS 6.1
CVE-2018-25091 [MEDIUM] python-pip vulnerabilities
python-pip vulnerabilities
USN-6473-1 fixed vulnerabilities in urllib3. This update provides the
corresponding updates for the urllib3 module bundled into pip.
Original advisory details:
It was discovered that urllib3 didn't strip HTTP Authorization header
on cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-25091)
It was discovered that urllib3 didn't strip HTTP Cookie header on
cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. (CVE-2023-43804)
It was discovered that urllib3 didn't strip HTTP body on status code
303 redirects under certain circumstances. A remote attacker could
possibly use this issue t
OSV
python-urllib3 vulnerabilities
osv·2023-11-07·CVSS 6.1
CVE-2018-25091 [MEDIUM] python-urllib3 vulnerabilities
python-urllib3 vulnerabilities
It was discovered that urllib3 didn't strip HTTP Authorization header
on cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-25091)
It was discovered that urllib3 didn't strip HTTP Cookie header on
cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. (CVE-2023-43804)
It was discovered that urllib3 didn't strip HTTP body on status code
303 redirects under certain circumstances. A remote attacker could
possibly use this issue to obtain sensitive information. (CVE-2023-45803)
GHSA
Authorization Header forwarded on redirect
ghsa·2023-10-15·CVSS 9.8
CVE-2018-25091 [CRITICAL] CWE-200 Authorization Header forwarded on redirect
Authorization Header forwarded on redirect
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
OSV
CVE-2018-25091: urllib3 before 1
osv·2023-10-15·CVSS 9.8
CVE-2018-25091 [CRITICAL] CVE-2018-25091: urllib3 before 1
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
OSV
Authorization Header forwarded on redirect
osv·2023-10-15·CVSS 9.8
CVE-2018-25091 [CRITICAL] Authorization Header forwarded on redirect
Authorization Header forwarded on redirect
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
No detection rules found.
No public exploits indexed.
https://github.com/urllib3/urllib3/commit/adb358f8e06865406d1f05e581a16cbea2136fbchttps://github.com/urllib3/urllib3/compare/1.24.1...1.24.2https://github.com/urllib3/urllib3/issues/1510https://github.com/urllib3/urllib3/commit/adb358f8e06865406d1f05e581a16cbea2136fbchttps://github.com/urllib3/urllib3/compare/1.24.1...1.24.2https://github.com/urllib3/urllib3/issues/1510
2023-10-15
Published