Information disclosure in urllib3 - CVE-2018-20060
Published: March 26, 2020 / Updated: November 10, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to Authorization HTTP header is not removed from the HTTP request during request redirection in "urllib3/util/retry.py". A remote attacker can intercept the request and gain access to sensitive information, passed via Authorization HTTP header.
Affected software
Amazon Linux AMI
CentOS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Fedora
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for ARM 64
Opensuse
Juniper Secure Analytics (JSA)
python-pip (Red Hat package)
python-virtualenv (Red Hat package)
toolbox-tests
toolbox
udica
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
aardvark-dns
python-urllib3 (Red Hat package)
netavark
fuse-overlayfs
crun
skopeo-tests
skopeo
python-urllib3
buildah-tests
buildah
containers-common
conmon
container-selinux
criu
criu-devel
criu-libs
crit
python3-criu
libslirp
libslirp-devel
python3-podman
podman-docker
podman-tests
podman-remote
podman-plugins
podman-gvproxy
podman-catatonit
podman
python-pip-epel
python3-virtualenv
cockpit-podman
QRadar Deployment Intelligence App
SOAR QRadar Plugin App
IBM Qradar SIEM
How to mitigate CVE-2018-20060
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
python-pip (Red Hat package) - addressed in versions 9.0.3-7.el7_7, 9.0.3-7.el7_8, 9.0.3-16.el8
python-virtualenv (Red Hat package) - addressed in versions 15.1.0-4.el7_7, 15.1.0-4.el7_8
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
udica - update to 0.2.6-21
runc - update to 1.1.12-1.0.1
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
containernetworking-plugins - update to 1.4.0-2.0.1
aardvark-dns - update to 1.10.0-2.0.1
python-urllib3 (Red Hat package) - update to 1.10.2-7.el7
netavark - update to 1.10.3-1.0.1
fuse-overlayfs - update to 1.13-1.0.1
crun - update to 1.14.3-2
skopeo-tests - update to 1.14.3-2.0.1
skopeo - update to 1.14.3-2.0.1
python-urllib3 - addressed in versions 1.24.2-1.fc28, 1.24.2-1.fc29, 1.24.2-1.fc30
buildah-tests - update to 1.33.7-1
buildah - update to 1.33.7-1
containers-common - update to 1-81.0.1
conmon - update to 2.1.10-1
container-selinux - update to 2.229.0-2
QRadar Deployment Intelligence App - update to 3.0.16
criu - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
libslirp - update to 4.4.0-2
libslirp-devel - update to 4.4.0-2
python3-podman - update to 4.9.0-1
podman-docker - update to 4.9.4-1.0.1
podman-tests - update to 4.9.4-1.0.1
podman-remote - update to 4.9.4-1.0.1
podman-plugins - update to 4.9.4-1.0.1
podman-gvproxy - update to 4.9.4-1.0.1
podman-catatonit - update to 4.9.4-1.0.1
podman - update to 4.9.4-1.0.1
SOAR QRadar Plugin App - update to 5.4.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 6
python-pip-epel - addressed in versions 8.1.2-11.el7, 8.1.2-12.el7
python3-virtualenv - update to 15.1.0-5.el7
cockpit-podman - update to 84.1-1
External References
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00039.html
- https://access.redhat.com/errata/RHSA-2019:2272
- https://bugzilla.redhat.com/show_bug.cgi?id=1649153
- https://github.com/urllib3/urllib3/blob/master/CHANGES.rst
- https://github.com/urllib3/urllib3/issues/1316
- https://github.com/urllib3/urllib3/pull/1346
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5SJERZEJDSUYQP7BNBXMBHRHGY26HRZD/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BXLAXHM3Z6DUCXZ7ZXZ2EAYJXWDCZFCT/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWP36YW3KSVLXDBY3QJKDYEPCIMN3VQZ/
- https://usn.ubuntu.com/3990-1/
Related Security Bulletins
- CentOS 7 update for python-virtualenv
- CentOS 7 update for python-pip
- OpenSUSE Linux update for python-urllib3
- Amazon Linux AMI update for python-urllib3
- Red Hat Enterprise Linux 8 update for python-pip
- Red Hat Enterprise Linux 8 update for the python27:2.7 module
- Red Hat Enterprise Linux 7 update for python-virtualenv
- Red Hat Enterprise Linux 7 update for python-pip
- Red Hat Enterprise Linux 7 update for python-urllib3
- Red Hat Enterprise Linux 7 update for python-pip
- Red Hat Enterprise Linux 7 update for python-virtualenv
- Multiple vulnerabilities in IBM QRadar SIEM
- Information disclosure in urllib3
- Multiple vulnerabilities in IBM SOAR QRadar Plugin App
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in IBM QRadar Deployment Intelligence App
- Anolis OS update for container-tools:an8 module
- Fedora 30 update for python-urllib3
- Fedora 28 update for python-urllib3
- Fedora 29 update for python-urllib3
- Fedora EPEL 7 update for python-pip-epel
- Fedora EPEL 7 update for python-pip-epel
- Fedora EPEL 7 update for python3-virtualenv