RHSA-2024:9922: Moderate: python3.11-urllib3 security update
Moderate: python3.11-urllib3 security update
Other sources
The python-urllib3 package provides the Python HTTP module with connection pooling and file POST abilities.Security Fix(es): urllib3: proxy-authorization request header is not stripped during cross-origin redirects (CVE-2024-37891) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:9922?
The severity of RHSA-2024:9922 is classified as moderate.
How do I fix RHSA-2024:9922?
To fix RHSA-2024:9922, update the python3.11-urllib3 package to version 1.26.12-2.el9_4.1.
What vulnerability does RHSA-2024:9922 address?
RHSA-2024:9922 addresses a vulnerability where the proxy-authorization request header is not stripped during cross-origin redirects.
Which systems are affected by RHSA-2024:9922?
RHSA-2024:9922 affects multiple versions of Red Hat Enterprise Linux including ARM 64, Power LE, x86_64, and IBM z Systems.
Is there a recommended version of the package to mitigate RHSA-2024:9922?
The recommended version to mitigate RHSA-2024:9922 is python3.11-urllib3 1.26.12-2.el9_4.1.