QID 995496
Date Published: 2023-10-03
QID 995496: Python (Pip) Security Update for urllib3 (GHSA-v845-jxx5-vc9f)
urllib3 doesn't treat the Cookie HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a Cookie header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-v845-jxx5-vc9f for updates and patch information.
Vendor References
- GHSA-v845-jxx5-vc9f -
github.com/advisories/GHSA-v845-jxx5-vc9f
CVEs related to QID 995496
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-v845-jxx5-vc9f | urllib3 |
|