urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.
References
Information
Published : 2018-12-11 09:29
Updated : 2021-06-15 14:15
NVD link : CVE-2018-20060
Mitre link : CVE-2018-20060
JSON object : View
CWE
Products Affected
python
- urllib3
fedoraproject
- fedora