Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-43804
HistoryOct 04, 2023 - 12:00 a.m.

CVE-2023-43804

2023-10-0400:00:00
ubuntu.com
ubuntu.com
14
urllib3
http client
python
cookie
information leakage
http redirects
security patch

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS

0.001

Percentile

39.2%

urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn’t
treat the Cookie HTTP header special or provide any helpers for managing
cookies over HTTP, that is the responsibility of the user. However, it is
possible for a user to specify a Cookie header and unknowingly leak
information via HTTP redirects to a different origin if that user doesn’t
disable redirects explicitly. This issue has been patched in urllib3
version 1.26.17 or 2.0.5.

Bugs

Notes

Author Note
mdeslaur On focal and earlier, the python-pip package bundles python-urllib3 binaries when built. After updating python-urllib3, a no-change rebuild of python-pip is required. On jammy and later, python-urllib3 is bundled in the python-pip package and needs to be patched.
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchpython-pip< 9.0.1-2.3~ubuntu1.18.04.8+esm2UNKNOWN
ubuntu20.04noarchpython-pip< 20.0.2-5ubuntu1.10UNKNOWN
ubuntu22.04noarchpython-pip< 22.0.2+dfsg-1ubuntu0.4UNKNOWN
ubuntu23.04noarchpython-pip< 23.0.1+dfsg-1ubuntu0.2UNKNOWN
ubuntu23.10noarchpython-pip< 23.2+dfsg-1ubuntu0.1UNKNOWN
ubuntu24.04noarchpython-pip< anyUNKNOWN
ubuntu14.04noarchpython-pip< anyUNKNOWN
ubuntu16.04noarchpython-pip< 8.1.1-2ubuntu0.6+esm6UNKNOWN
ubuntu18.04noarchpython-urllib3< 1.22-1ubuntu0.18.04.2+esm1UNKNOWN
ubuntu20.04noarchpython-urllib3< 1.25.8-2ubuntu0.3UNKNOWN
Rows per page:
1-10 of 151

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS

0.001

Percentile

39.2%