urllib3: urllib3 does not remove the authorization HTTP header when following a cross-origin redirect
Published Oct 15, 2023
5.3
MEDIUMCVSS 4.0
EPSS 0.52%
Description
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
Affected products
No data.
No data.
Red Hat Enterprise Linux 8
container-tools:rhel8-8100020240227110532.82888897
Fixed · RHSA-2024:2988
Red Hat Ansible Automation Platform 2
python-urllib3
Affected
Red Hat Certification for Red Hat Enterprise Linux 8
redhat-certification-baremetal-container
Not affected
Red Hat Developer Hub
rhdh/rhdh-hub-rhel9
Not affected
Red Hat Enterprise Linux 6
python-urllib3
Out of support scope
Red Hat Enterprise Linux 7
python-pip
Out of support scope
Red Hat Enterprise Linux 7
python-s3transfer
Out of support scope
Red Hat Enterprise Linux 7
python-urllib3
Out of support scope
Red Hat Enterprise Linux 7
resource-agents
Out of support scope
Red Hat Enterprise Linux 8
inkscape:flatpak/python2-pip
Not affected
Red Hat Enterprise Linux 8
python-pip
Not affected
Red Hat Enterprise Linux 8
python-urllib3
Not affected
Red Hat Enterprise Linux 8
python27:2.7/python-urllib3
Not affected
Red Hat Enterprise Linux 8
python27:2.7/python2-pip
Not affected
Red Hat Enterprise Linux 8
python3.11-pip
Not affected
Red Hat Enterprise Linux 8
python39:3.9/python-urllib3
Not affected
Red Hat Enterprise Linux 8
python39:3.9/python3x-pip
Not affected
Red Hat Enterprise Linux 9
fence-agents
Not affected
Red Hat Enterprise Linux 9
python-pip
Not affected
Red Hat Enterprise Linux 9
python-urllib3
Not affected
Red Hat Enterprise Linux 9
python3.11-pip
Not affected
Red Hat OpenShift Container Platform 3.11
python-urllib3
Out of support scope
Red Hat OpenShift Container Platform 4
openshift4/baremetal-hardware-event-proxy-rhel8
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ztp-site-generate-rhel8
Not affected
Red Hat OpenShift Data Science (RHODS)
rhods/odh-ml-pipelines-cache-rhel8
Affected
Red Hat OpenStack Platform 17.1
python-urllib3
Not affected
Red Hat Quay 3
quay/quay-rhel8
Affected
Red Hat Satellite 6
ansiblerole-foreman_scap_client
Not affected
Red Hat Satellite 6
python-urllib3
Not affected
Red Hat Software Collections
rh-python38-python-pip
Not affected
Red Hat Software Collections
rh-python38-python-urllib3
Not affected
Red Hat Storage 3
graphite-web
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | container-tools:rhel8-8100020240227110532.82888897 | Fixed | RHSA-2024:2988 |
| Red Hat Ansible Automation Platform 2 | python-urllib3 | Affected | n/a |
| Red Hat Certification for Red Hat Enterprise Linux 8 | redhat-certification-baremetal-container | Not affected | n/a |
| Red Hat Developer Hub | rhdh/rhdh-hub-rhel9 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | python-urllib3 | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | python-pip | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | python-s3transfer | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | python-urllib3 | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | resource-agents | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | inkscape:flatpak/python2-pip | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python-pip | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python-urllib3 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python27:2.7/python-urllib3 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python27:2.7/python2-pip | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python3.11-pip | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python39:3.9/python-urllib3 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python39:3.9/python3x-pip | Not affected | n/a |
| Red Hat Enterprise Linux 9 | fence-agents | Not affected | n/a |
| Red Hat Enterprise Linux 9 | python-pip | Not affected | n/a |
| Red Hat Enterprise Linux 9 | python-urllib3 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | python3.11-pip | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | python-urllib3 | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/baremetal-hardware-event-proxy-rhel8 | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ztp-site-generate-rhel8 | Not affected | n/a |
| Red Hat OpenShift Data Science (RHODS) | rhods/odh-ml-pipelines-cache-rhel8 | Affected | n/a |
| Red Hat OpenStack Platform 17.1 | python-urllib3 | Not affected | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Affected | n/a |
| Red Hat Satellite 6 | ansiblerole-foreman_scap_client | Not affected | n/a |
| Red Hat Satellite 6 | python-urllib3 | Not affected | n/a |
| Red Hat Software Collections | rh-python38-python-pip | Not affected | n/a |
| Red Hat Software Collections | rh-python38-python-urllib3 | Not affected | n/a |
| Red Hat Storage 3 | graphite-web | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This is only exploitable if a redirect differs in host, port, or scheme. Due to the credential exposure in the authorization header, the confidentiality is highly impacted, but there is no proof that the integrity is affected in any way.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 16, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (6 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.52% (0.00516) | 41.80th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.51% (0.00512) | 39.35th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.25% (0.00250) | 46.44th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.11% (0.00109) | 45.70th | v3 (v2023.03.01) |
| Oct 20, 2023 | 0.07% (0.00072) | 29.99th | v3 (v2023.03.01) |
| Oct 16, 2023 | 0.04% (0.00045) | 12.52th | v3 (v2023.03.01) |
References (10)
- https://access.redhat.com/security/cve/CVE-2018-25091 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2244340 Issue Tracking
- https://github.com/advisories/GHSA-gwvm-45gx-3cf8 Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2023-207.yaml
- https://github.com/urllib3/urllib3/commit/adb358f8e06865406d1f05e581a16cbea2136fbc Patch
- https://github.com/urllib3/urllib3/compare/1.24.1...1.24.2 Patch
- https://github.com/urllib3/urllib3/issues/1510 Issue TrackingPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-25091
- https://security.snyk.io/vuln/SNYK-PYTHON-URLLIB3-5969479
- https://www.cve.org/CVERecord?id=CVE-2018-25091
Change history (0)
No recorded changes yet.