USN-7084-1: urllib3 vulnerability
Published Oct 29, 2024
·Updated
It was discovered that urllib3 didn't strip HTTP Proxy-Authorization header on cross-origin redirects. A remote attacker could possibly use this issue to obtain sensitive information.
Affected Software
16 affected componentsFixes available
All of the following
ubuntu/python3-urllib3<2.0.7-2ubuntu0.1
2.0.7-2ubuntu0.1
Ubuntu Ubuntu=24.10
All of the following
ubuntu/python3-urllib3<2.0.7-1ubuntu0.1
2.0.7-1ubuntu0.1
Ubuntu Ubuntu=24.04
All of the following
ubuntu/python3-urllib3<1.26.5-1~exp1ubuntu0.2
1.26.5-1~exp1ubuntu0.2
Ubuntu Ubuntu=22.04
All of the following
ubuntu/python3-urllib3<1.25.8-2ubuntu0.4
1.25.8-2ubuntu0.4
Ubuntu Ubuntu=20.04
All of the following
ubuntu/python-urllib3<1.22-1ubuntu0.18.04.2+esm2
1.22-1ubuntu0.18.04.2+esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/python3-urllib3<1.22-1ubuntu0.18.04.2+esm2
1.22-1ubuntu0.18.04.2+esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/python-urllib3<1.13.1-2ubuntu0.16.04.4+esm2
1.13.1-2ubuntu0.16.04.4+esm2
Ubuntu Ubuntu=16.04
All of the following
ubuntu/python3-urllib3<1.13.1-2ubuntu0.16.04.4+esm2
1.13.1-2ubuntu0.16.04.4+esm2
Ubuntu Ubuntu=16.04
Event History
Oct 29, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7084-1?
The severity of USN-7084-1 is considered to be moderate due to the potential for sensitive information leakage.
2
How do I fix USN-7084-1?
To fix USN-7084-1, update urllib3 to the recommended versions specified in the advisory.
3
What software is affected by USN-7084-1?
USN-7084-1 affects multiple versions of python3-urllib3 across several Ubuntu releases.
4
Can USN-7084-1 be exploited remotely?
Yes, USN-7084-1 could potentially be exploited remotely by an attacker to gain sensitive information.
5
What is the impact of not addressing USN-7084-1?
Not addressing USN-7084-1 may lead to unauthorized access to sensitive data transmitted through HTTP.