QID 982226

QID 982226: Python (pip) Security Update for urllib3 (GHSA-www2-v7xj-xrc6)

urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-www2-v7xj-xrc6 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982226

    Software Advisories
    Advisory ID Software Component Link
    GHSA-www2-v7xj-xrc6 urllib3 URL Logo github.com/advisories/GHSA-www2-v7xj-xrc6