CVE-2018-20060

CRITICAL

urllib3 <1.23 - Info Disclosure

Title source: llm

Description

urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.

Scores

CVSS v3 9.8
EPSS 0.0043
EPSS Percentile 62.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

Status published

Affected Products (5)

python/urllib3 < 1.23
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
pypi/urllib3 < 1.23PyPI

Timeline

Published Dec 11, 2018
Tracked Since Feb 18, 2026