vulnerability
Oracle Linux: CVE-2018-20060: ELSA-2019-2272: python-urllib3 security update (MODERATE) (Multiple Advisories)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:P/I:N/A:N) | Mar 26, 2018 | Aug 20, 2019 | Dec 3, 2025 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Mar 26, 2018
Added
Aug 20, 2019
Modified
Dec 3, 2025
Description
urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.
Solutions
oracle-linux-upgrade-babeloracle-linux-upgrade-platform-python-piporacle-linux-upgrade-python2oracle-linux-upgrade-python2-attrsoracle-linux-upgrade-python2-babeloracle-linux-upgrade-python2-backportsoracle-linux-upgrade-python2-backports-ssl-match-hostnameoracle-linux-upgrade-python2-bsonoracle-linux-upgrade-python2-chardetoracle-linux-upgrade-python2-coverageoracle-linux-upgrade-python2-cythonoracle-linux-upgrade-python2-debugoracle-linux-upgrade-python2-develoracle-linux-upgrade-python2-dnsoracle-linux-upgrade-python2-docsoracle-linux-upgrade-python2-docs-infooracle-linux-upgrade-python2-docutilsoracle-linux-upgrade-python2-funcsigsoracle-linux-upgrade-python2-idnaoracle-linux-upgrade-python2-ipaddressoracle-linux-upgrade-python2-jinja2oracle-linux-upgrade-python2-libsoracle-linux-upgrade-python2-lxmloracle-linux-upgrade-python2-markupsafeoracle-linux-upgrade-python2-mockoracle-linux-upgrade-python2-noseoracle-linux-upgrade-python2-numpyoracle-linux-upgrade-python2-numpy-docoracle-linux-upgrade-python2-numpy-f2pyoracle-linux-upgrade-python2-piporacle-linux-upgrade-python2-pip-wheeloracle-linux-upgrade-python2-pluggyoracle-linux-upgrade-python2-psycopg2oracle-linux-upgrade-python2-psycopg2-debugoracle-linux-upgrade-python2-psycopg2-testsoracle-linux-upgrade-python2-pyoracle-linux-upgrade-python2-pygmentsoracle-linux-upgrade-python2-pymongooracle-linux-upgrade-python2-pymongo-gridfsoracle-linux-upgrade-python2-pymysqloracle-linux-upgrade-python2-pysocksoracle-linux-upgrade-python2-pytestoracle-linux-upgrade-python2-pytest-mockoracle-linux-upgrade-python2-pytzoracle-linux-upgrade-python2-pyyamloracle-linux-upgrade-python2-requestsoracle-linux-upgrade-python2-rpm-macrosoracle-linux-upgrade-python2-scipyoracle-linux-upgrade-python2-setuptoolsoracle-linux-upgrade-python2-setuptools-scmoracle-linux-upgrade-python2-setuptools-wheeloracle-linux-upgrade-python2-sixoracle-linux-upgrade-python2-sqlalchemyoracle-linux-upgrade-python2-testoracle-linux-upgrade-python2-tkinteroracle-linux-upgrade-python2-toolsoracle-linux-upgrade-python2-urllib3oracle-linux-upgrade-python2-virtualenvoracle-linux-upgrade-python2-wheeloracle-linux-upgrade-python2-wheel-wheeloracle-linux-upgrade-python3-piporacle-linux-upgrade-python3-pip-wheeloracle-linux-upgrade-python-nose-docsoracle-linux-upgrade-python-psycopg2-docoracle-linux-upgrade-python-sqlalchemy-docoracle-linux-upgrade-python-urllib3oracle-linux-upgrade-python-virtualenv
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.