Lucene search

K
f5F5F5:K000133668
HistoryApr 27, 2023 - 12:00 a.m.

K000133668 : Python urllib3 vulnerability CVE-2018-20060

2023-04-2700:00:00
my.f5.com
8
python urllib3
vulnerability
cve-2018-20060
authorization header
cross-origin redirect
credentials
cleartext

6.7 Medium

AI Score

Confidence

Low

0.01 Low

EPSS

Percentile

83.8%

Security Advisory Description

urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext. (CVE-2018-20060)

Impact

For products with None in theVersions known to be vulnerable column, there is no impact.

This vulnerability may allow credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.