Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2018-20060

Published: 11 December 2018

urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.

Priority

Low

Cvss 3 Severity Score

9.8

Score breakdown

Status

Package Release Status
python-urllib3
Launchpad, Ubuntu, Debian
bionic
Released (1.22-1ubuntu0.18.04.1)
cosmic
Released (1.22-1ubuntu0.18.10.1)
disco Not vulnerable
(1.24-1)
eoan Not vulnerable
(1.24-1)
focal Not vulnerable
(1.24-1)
groovy Not vulnerable
(1.24-1)
hirsute Not vulnerable
(1.24-1)
impish Not vulnerable
(1.24-1)
jammy Not vulnerable
(1.24-1)
kinetic Not vulnerable
(1.24-1)
lunar Not vulnerable
(1.24-1)
mantic Not vulnerable
(1.24-1)
trusty Needed

upstream
Released (1.24-1)
xenial
Released (1.13.1-2ubuntu0.16.04.3)
Patches:
upstream: https://github.com/urllib3/urllib3/pull/1346
upstream: https://github.com/urllib3/urllib3/commit/3d7f98b07b6e6e04c2e89cdf5afb18024a2d804c
upstream: https://github.com/urllib3/urllib3/commit/f99912beeaf230ee3634b938d3ea426ffd1f3e57
upstream: https://github.com/urllib3/urllib3/commit/48dba048081dfcb999afcda715d17147aa15b6ea
upstream: https://github.com/urllib3/urllib3/commit/23e2eb56af23db5a1eeb8ad9b51dd99a27c15522
upstream: https://github.com/urllib3/urllib3/commit/5e9c6b9175d66170ef65fc703f2e46788a59ca0c
upstream: https://github.com/urllib3/urllib3/commit/9c9dd6f3014e89bb9c532b641abcf1b24c3896ab
upstream: https://github.com/urllib3/urllib3/commit/6245ddddb7f80740c5c15e1750e5b9f68c5b2b5f
upstream: https://github.com/urllib3/urllib3/commit/3b5f27449e153ad05186beca8fbd9b134936fe50
upstream: https://github.com/urllib3/urllib3/commit/1742538d57865e61125c6c12a755b5db41636fe7
upstream: https://github.com/urllib3/urllib3/commit/2a42e70ff077006d5a6da92251ddbb2939303f94
upstream: https://github.com/urllib3/urllib3/commit/e8a727a0b8389f5f75981858a8bbb319646f4450
upstream: https://github.com/urllib3/urllib3/commit/63948f3a607ed8e7a3ce9ac4e20782359896e27e

Severity score breakdown

Parameter Value
Base score 9.8
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H