[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-MGASA-2019-0258":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T08:55:32.481Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":20,"duplicates":21,"related":22,"reserved_at":9,"published_at":26,"modified_at":27,"state":9,"summary":28,"references_raw":30,"kevs":47,"epss":9,"epss_history":48,"metrics":49,"affected":50},"MGASA-2019-0258","Updated python-urllib3 packages fix security vulnerability\n\nIt was discovered that urllib3 incorrectly removed Authorization HTTP\nheaders when handled cross-origin redirects. This could result in\ncredentials being sent to unintended hosts (CVE-2018-20060).\n\nIt was discovered that urllib3 incorrectly stripped certain characters\nfrom requests. A remote attacker could use this issue to perform CRLF\ninjection (CVE-2019-11236).\n\nIt was discovered that urllib3 incorrectly handled situations where a\ndesired set of CA certificates were specified. This could result in\ncertificates being accepted by the default CA certificates contrary to\nexpectatons (CVE-2019-11324).\n\nThe python-urllib3 package has been updated to version 1.24.3 to fix these\nissues and other bugs.  The python-requests package has been fixed to work\nwith the updated python-urllib3\n",null,[],[],[],[14,16,18],{"_key":15},"CVE-2018-20060",{"_key":17},"CVE-2019-11236",{"_key":19},"CVE-2019-11324",[],[],[23,24,25],{"_key":15},{"_key":17},{"_key":19},"2019-09-06T21:09:08Z","2026-04-16T04:26:19.914254Z",{"cisa_kev":29,"cisa_ransomware":29,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[31,37,42],{"url":32,"sources":33,"tags":35},"https://advisories.mageia.org/MGASA-2019-0258.html",[34],"osv_mageia",[36],"Advisory",{"url":38,"sources":39,"tags":40},"https://bugs.mageia.org/show_bug.cgi?id=23880",[34],[41],"REPORT",{"url":43,"sources":44,"tags":45},"https://usn.ubuntu.com/3990-1/",[34],[41,46],"WEB",[],[],[],[51,63],{"ecosystem":52,"name":53,"vendor":54,"product":53,"cpe_part":9,"purl_type":55,"purl_namespace":54,"purl_name":53,"source":9,"versions":56},"Mageia","python-requests","mageia","rpm",[57],{"version":58,"is_range":59,"range_type":60,"version_start":9,"version_start_type":9,"version_end":61,"version_end_type":62,"fixed_in":9},"lt2_11_1_2_2_mga6",true,"ecosystem","2.11.1-2.2.mga6","excluding",{"ecosystem":52,"name":64,"vendor":54,"product":64,"cpe_part":9,"purl_type":55,"purl_namespace":54,"purl_name":64,"source":9,"versions":65},"python-urllib3",[66],{"version":67,"is_range":59,"range_type":60,"version_start":9,"version_start_type":9,"version_end":68,"version_end_type":62,"fixed_in":9},"lt1_24_3_1_mga6","1.24.3-1.mga6"]