CVE-2018-20060

Aliases:GHSA-www2-v7xj-xrc6PYSEC-2018-32
Modified
Published: 11 Dec 2018, 17:00
Last modified:27 Dec 2024, 16:02

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.0 (nvd)
EPSS Score
0.66% LOW
1% probability +0.18%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

11 Dec 2018, 17:00
Published
Vulnerability first disclosed
27 Dec 2024, 16:02
Last Modified
Vulnerability information updated

Description

urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.

CVSS Metrics

  • v4.0CRITICALScore: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  • v3.0CRITICALScore: 9.8CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.66% Percentile: 71%

Affected Systems

  • fedoraprojectfedora

    28 | 29 | 30

  • PyPIurllib3

    < 1.23

  • pythonurllib3

    < 1.23

References (28)