PT-2023-7669 · Pypi+11 · Urllib3+11

Ranjit-Git

·

Published

2023-10-02

·

Updated

2026-06-03

·

CVE-2023-43804

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions urllib3 versions prior to 1.26.17 urllib3 versions prior to 2.0.5
Description The issue is related to the handling of the Cookie HTTP header in urllib3, a user-friendly HTTP client library for Python. If a user specifies a Cookie header and does not disable redirects explicitly, it is possible to leak information via HTTP redirects to a different origin. The number of usages affected by this advisory is believed to be low, requiring specific conditions to be met, including the use of an affected version of urllib3, the Cookie header on requests, not disabling HTTP redirects, and either not using HTTPS or the origin server redirecting to a malicious origin.
Recommendations For versions prior to 1.26.17, upgrade to at least urllib3 version 1.26.17. For versions prior to 2.0.5, upgrade to at least urllib3 version 2.0.5. As a temporary workaround, consider disabling HTTP redirects using redirects=False when sending requests. Avoid using the Cookie header on requests unless necessary, and ensure that redirects are properly handled to prevent information leakage.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:7753
ALSA-2024:0116
ALSA-2024:0133
ALSA-2024:0464
ALSA-2024:2159
ALSA-2024:2985
ALSA-2024:2986
ALSA-2024:2987
ALT-PU-2023-8072
ALT-PU-2024-15946
ALT-PU-2024-16020
ALT-PU-2024-9139
AZL-31108
AZL-35444
AZL-59696
BDU:2023-08730
CESA-2024_0116
CESA-2024_0133
CESA-2024_2985
CESA-2024_2986
CESA-2024_2987
CVE-2023-43804
DLA-3610-1
DLA-3998-1
GHSA-V845-JXX5-VC9F
INFSA-2024_2159
INFSA-2024_2985
INFSA-2024_2986
INFSA-2024_2987
OESA-2023-1707
OESA-2024-1867
OESA-2024-1868
OESA-2024-1869
OPENSUSE-SU-2024:13301-1
OPENSUSE-SU-2024:13302-1
PYSEC-2023-192
RHSA-2023:6158
RHSA-2023:6812
RHSA-2023:7378
RHSA-2023:7385
RHSA-2023:7407
RHSA-2023:7435
RHSA-2023:7523
RHSA-2023:7528
RHSA-2023:7753
RHSA-2023:7851
RHSA-2023_7753
RHSA-2024:0116
RHSA-2024:0133
RHSA-2024:0187
RHSA-2024:0300
RHSA-2024:0464
RHSA-2024:0588
RHSA-2024:0733
RHSA-2024:2159
RHSA-2024:2985
RHSA-2024:2986
RHSA-2024:2987
RHSA-2024_0116
RHSA-2024_0133
RHSA-2024_0464
RHSA-2024_2159
RHSA-2024_2985
RHSA-2024_2986
RHSA-2024_2987
RLSA-2024:2985
RLSA-2024:2986
SUSE-SU-2023:4064-1
SUSE-SU-2023:4108-1
SUSE-SU-2023:4157-1
SUSE-SU-2023:4352-1
SUSE-SU-2023_4064-1
SUSE-SU-2023_4108-1
USN-6473-1
USN-6473-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Urllib3