CVE-2018-20060
CRITICALurllib3 <1.23 - Info Disclosure
Title source: llmDescription
urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.
Scores
CVSS v3
9.8
EPSS
0.0043
EPSS Percentile
62.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
Status
published
Affected Products (5)
python/urllib3
< 1.23
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
pypi/urllib3
< 1.23PyPI
Timeline
Published
Dec 11, 2018
Tracked Since
Feb 18, 2026