Information disclosure in urllib3 - CVE-2018-20060

 

Information disclosure in urllib3 - CVE-2018-20060

Published: March 26, 2020 / Updated: November 10, 2023


Vulnerability identifier: #VU26413
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-20060
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to Authorization HTTP header is not removed from the HTTP request during request redirection in "urllib3/util/retry.py". A remote attacker can intercept the request and gain access to sensitive information, passed via Authorization HTTP header.


Affected software

urllib3
Amazon Linux AMI
CentOS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Fedora
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for ARM 64
Opensuse
Juniper Secure Analytics (JSA)
python-pip (Red Hat package)
python-virtualenv (Red Hat package)
toolbox-tests
toolbox
udica
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
aardvark-dns
python-urllib3 (Red Hat package)
netavark
fuse-overlayfs
crun
skopeo-tests
skopeo
python-urllib3
buildah-tests
buildah
containers-common
conmon
container-selinux
criu
criu-devel
criu-libs
crit
python3-criu
libslirp
libslirp-devel
python3-podman
podman-docker
podman-tests
podman-remote
podman-plugins
podman-gvproxy
podman-catatonit
podman
python-pip-epel
python3-virtualenv
cockpit-podman
QRadar Deployment Intelligence App
SOAR QRadar Plugin App
IBM Qradar SIEM

How to mitigate CVE-2018-20060

Install updates from vendor's website.

urllib3 - update to 1.23
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
python-pip (Red Hat package) - addressed in versions 9.0.3-7.el7_7, 9.0.3-7.el7_8, 9.0.3-16.el8
python-virtualenv (Red Hat package) - addressed in versions 15.1.0-4.el7_7, 15.1.0-4.el7_8
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
udica - update to 0.2.6-21
runc - update to 1.1.12-1.0.1
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
containernetworking-plugins - update to 1.4.0-2.0.1
aardvark-dns - update to 1.10.0-2.0.1
python-urllib3 (Red Hat package) - update to 1.10.2-7.el7
netavark - update to 1.10.3-1.0.1
fuse-overlayfs - update to 1.13-1.0.1
crun - update to 1.14.3-2
skopeo-tests - update to 1.14.3-2.0.1
skopeo - update to 1.14.3-2.0.1
python-urllib3 - addressed in versions 1.24.2-1.fc28, 1.24.2-1.fc29, 1.24.2-1.fc30
buildah-tests - update to 1.33.7-1
buildah - update to 1.33.7-1
containers-common - update to 1-81.0.1
conmon - update to 2.1.10-1
container-selinux - update to 2.229.0-2
QRadar Deployment Intelligence App - update to 3.0.16
criu - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
libslirp - update to 4.4.0-2
libslirp-devel - update to 4.4.0-2
python3-podman - update to 4.9.0-1
podman-docker - update to 4.9.4-1.0.1
podman-tests - update to 4.9.4-1.0.1
podman-remote - update to 4.9.4-1.0.1
podman-plugins - update to 4.9.4-1.0.1
podman-gvproxy - update to 4.9.4-1.0.1
podman-catatonit - update to 4.9.4-1.0.1
podman - update to 4.9.4-1.0.1
SOAR QRadar Plugin App - update to 5.4.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 6
python-pip-epel - addressed in versions 8.1.2-11.el7, 8.1.2-12.el7
python3-virtualenv - update to 15.1.0-5.el7
cockpit-podman - update to 84.1-1

External References

Related Security Bulletins