RHSA-2024:8035: Moderate: python3.11-urllib3 security update
Moderate: python3.11-urllib3 security update
Other sources
The python-urllib3 package provides the Python HTTP module with connection pooling and file POST abilities.Security Fix(es): urllib3: proxy-authorization request header is not stripped during cross-origin redirects (CVE-2024-37891) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:8035?
The severity of RHSA-2024:8035 is classified as moderate.
How do I fix RHSA-2024:8035?
To fix RHSA-2024:8035, update the python3.11-urllib3 package to version 1.26.12-1.el8_8.1.
What vulnerability is addressed in RHSA-2024:8035?
RHSA-2024:8035 addresses a vulnerability where the proxy-authorization request header is not stripped during cross-origin redirects.
Which systems are affected by RHSA-2024:8035?
RHSA-2024:8035 affects various versions of Red Hat Enterprise Linux for x86_64, ARM 64, Power LE, and IBM z Systems.
Is there a specific package impacted by RHSA-2024:8035?
Yes, the specific package impacted by RHSA-2024:8035 is python3.11-urllib3.