Authorization Header forwarded on redirect
Moderate severity
GitHub Reviewed
Published
Oct 15, 2023
to the GitHub Advisory Database
•
Updated Nov 6, 2023
Description
Published by the National Vulnerability Database
Oct 15, 2023
Published to the GitHub Advisory Database
Oct 15, 2023
Reviewed
Oct 17, 2023
Last updated
Nov 6, 2023
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
References