CVE Vulnerabilities

CVE-2018-20060

Published: Dec 11, 2018 | Modified: Dec 27, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.

Affected Software

NameVendorStart VersionEnd Version
Urllib3Python*1.23 (excluding)
Red Hat Ansible Tower 3.5 for RHEL 7RedHatansible-tower-35/ansible-tower:3.5.6-1*
Red Hat Ansible Tower 3.6 for RHEL 7RedHatansible-tower-36/ansible-tower:3.6.4-1*
Red Hat Enterprise Linux 7RedHatpython-urllib3-0:1.10.2-7.el7*
Red Hat Enterprise Linux 7RedHatpython-pip-0:9.0.3-7.el7_7*
Red Hat Enterprise Linux 7RedHatpython-virtualenv-0:15.1.0-4.el7_7*
Red Hat Enterprise Linux 7RedHatpython-pip-0:9.0.3-7.el7_8*
Red Hat Enterprise Linux 7RedHatpython-virtualenv-0:15.1.0-4.el7_8*
Red Hat Enterprise Linux 8RedHatpython27:2.7-8020020200117110429.90f98d4f*
Red Hat Enterprise Linux 8RedHatpython-pip-0:9.0.3-16.el8*
Red Hat Enterprise Linux 8RedHatpython-pip-0:9.0.3-16.el8*
Python-urllib3Ubuntubionic*
Python-urllib3Ubuntucosmic*
Python-urllib3Ubuntuesm-infra-legacy/trusty*
Python-urllib3Ubuntuesm-infra/bionic*
Python-urllib3Ubuntuesm-infra/xenial*
Python-urllib3Ubuntutrusty*
Python-urllib3Ubuntutrusty/esm*
Python-urllib3Ubuntuupstream*
Python-urllib3Ubuntuxenial*

References