Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2018-20060
Description:urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.
Test IDs: 1.3.6.1.4.1.25623.1.1.2.2019.1877   1.3.6.1.4.1.25623.1.0.875583   1.3.6.1.4.1.25623.1.0.876047   1.3.6.1.4.1.25623.1.1.2.2024.1296   1.3.6.1.4.1.25623.1.1.1.2.2023.3610   1.3.6.1.4.1.25623.1.1.2.2019.1936   1.3.6.1.4.1.25623.1.0.892686   1.3.6.1.4.1.25623.1.1.2.2024.1703   1.3.6.1.4.1.25623.1.1.2.2024.1295   1.3.6.1.4.1.25623.1.1.2.2019.2362   1.3.6.1.4.1.25623.1.1.2.2024.1702  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2018-20060
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWP36YW3KSVLXDBY3QJKDYEPCIMN3VQZ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BXLAXHM3Z6DUCXZ7ZXZ2EAYJXWDCZFCT/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5SJERZEJDSUYQP7BNBXMBHRHGY26HRZD/
https://bugzilla.redhat.com/show_bug.cgi?id=1649153
https://github.com/urllib3/urllib3/blob/master/CHANGES.rst
https://github.com/urllib3/urllib3/issues/1316
https://github.com/urllib3/urllib3/pull/1346
https://lists.debian.org/debian-lts-announce/2021/06/msg00015.html
RedHat Security Advisories: RHSA-2019:2272
https://access.redhat.com/errata/RHSA-2019:2272
SuSE Security Announcement: openSUSE-SU-2019:2131 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00039.html
https://usn.ubuntu.com/3990-1/




© 1998-2025 E-Soft Inc. All rights reserved.