First published: Wed Oct 30 2024(Updated: )
USN-7084-1 fixed vulnerability in urllib3. This update provides the corresponding update for the urllib3 module bundled into pip. Original advisory details: It was discovered that urllib3 didn't strip HTTP Proxy-Authorization header on cross-origin redirects. A remote attacker could possibly use this issue to obtain sensitive information.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/python3-pip | <24.2+dfsg-1ubuntu0.1 | 24.2+dfsg-1ubuntu0.1 |
Ubuntu Ubuntu | =24.10 | |
All of | ||
ubuntu/python3-pip-whl | <24.2+dfsg-1ubuntu0.1 | 24.2+dfsg-1ubuntu0.1 |
Ubuntu Ubuntu | =24.10 | |
All of | ||
ubuntu/python3-pip | <24.0+dfsg-1ubuntu1.1 | 24.0+dfsg-1ubuntu1.1 |
Ubuntu Ubuntu | =24.04 | |
All of | ||
ubuntu/python3-pip-whl | <24.0+dfsg-1ubuntu1.1 | 24.0+dfsg-1ubuntu1.1 |
Ubuntu Ubuntu | =24.04 | |
All of | ||
ubuntu/python3-pip | <22.0.2+dfsg-1ubuntu0.5 | 22.0.2+dfsg-1ubuntu0.5 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/python3-pip-whl | <22.0.2+dfsg-1ubuntu0.5 | 22.0.2+dfsg-1ubuntu0.5 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/python-pip-whl | <20.0.2-5ubuntu1.11 | 20.0.2-5ubuntu1.11 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/python3-pip | <20.0.2-5ubuntu1.11 | 20.0.2-5ubuntu1.11 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/python-pip | <9.0.1-2.3~ubuntu1.18.04.8+esm6 | 9.0.1-2.3~ubuntu1.18.04.8+esm6 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/python-pip-whl | <9.0.1-2.3~ubuntu1.18.04.8+esm6 | 9.0.1-2.3~ubuntu1.18.04.8+esm6 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/python3-pip | <9.0.1-2.3~ubuntu1.18.04.8+esm6 | 9.0.1-2.3~ubuntu1.18.04.8+esm6 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/python-pip | <8.1.1-2ubuntu0.6+esm10 | 8.1.1-2ubuntu0.6+esm10 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/python-pip-whl | <8.1.1-2ubuntu0.6+esm10 | 8.1.1-2ubuntu0.6+esm10 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/python3-pip | <8.1.1-2ubuntu0.6+esm10 | 8.1.1-2ubuntu0.6+esm10 |
Ubuntu Ubuntu | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.