USN-7084-2: pip vulnerability
USN-7084-1 fixed vulnerability in urllib3. This update provides the corresponding update for the urllib3 module bundled into pip. Original advisory details: It was discovered that urllib3 didn't strip HTTP Proxy-Authorization header on cross-origin redirects. A remote attacker could possibly use this issue to obtain sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7084-2?
USN-7084-2 addresses a medium severity vulnerability in the urllib3 module affecting pip.
How do I fix USN-7084-2?
To fix USN-7084-2, update to the patched versions of python3-pip or python3-pip-whl provided in the advisory.
What versions of Ubuntu are affected by USN-7084-2?
USN-7084-2 affects specific versions of Ubuntu including 22.04, 24.04, and 24.10.
What does the vulnerability in USN-7084-2 allow an attacker to do?
The vulnerability allows remote attackers to potentially access sensitive information due to improper handling of HTTP Proxy-Authorization headers.
Is USN-7084-2 related to previous vulnerabilities?
Yes, USN-7084-1 was an earlier advisory that addressed a related vulnerability in urllib3.