Information disclosure in urllib3 - CVE-2018-25091
Published: November 10, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to urllib3 does not remove the authorization HTTP header when following a cross-origin redirect. A remote attacker can gain access to sensitive information.
Note, the vulnerability exists due to incomplete fix for #VU26413 (CVE-2018-20060).
Affected software
SUSE Linux Enterprise Server 12
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
Ubuntu
IBM Cloud Pak for Multicloud Management
Dell EMC PowerProtect Data Protection
SmartFabric OS10
Platform Automation Toolkit
RecoverPoint for Virtual Machines
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
python-pip (Ubuntu package)
python-pip-whl (Ubuntu package)
python3-pip (Ubuntu package)
python3-urllib3 (Ubuntu package)
python-urllib3 (Ubuntu package)
toolbox
toolbox-tests
udica
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
aardvark-dns
netavark
fuse-overlayfs
crun
skopeo-tests
skopeo
python-urllib3
buildah
buildah-tests
containers-common
conmon
container-selinux
python3-criu
crit
criu
criu-devel
criu-libs
libslirp-devel
libslirp
python3-podman
podman
podman-catatonit
podman-gvproxy
podman-plugins
podman-remote
podman-tests
podman-docker
python3-pip-whl (Ubuntu package)
cockpit-podman
IBM Spectrum Symphony
IBM Security Verify Access
How to mitigate CVE-2018-25091
IBM Cloud Pak for Multicloud Management - update to 2.3.8
Dell EMC PowerProtect Data Protection - update to 2.7.8
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
SmartFabric OS10 - addressed in versions 10.5.4.11, 10.5.6.1
python-pip (Ubuntu package) - update to Ubuntu Pro
python-pip-whl (Ubuntu package) - addressed in versions Ubuntu Pro, 20.0.2-5ubuntu1.10
python3-pip (Ubuntu package) - addressed in versions Ubuntu Pro, 20.0.2-5ubuntu1.10, 22.0.2+dfsg-1ubuntu0.4, 23.0.1+dfsg-1ubuntu0.2, 23.2+dfsg-1ubuntu0.1
python3-urllib3 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.25.8-2ubuntu0.3, 1.26.5-1~exp1ubuntu0.1, 1.26.12-1ubuntu0.1, 1.26.16-1ubuntu0.1
python-urllib3 (Ubuntu package) - update to Ubuntu Pro
toolbox - update to 0.0.99.5-2.0.1
toolbox-tests - update to 0.0.99.5-2.0.1
udica - update to 0.2.6-21
runc - update to 1.1.12-1.0.1
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
containernetworking-plugins - update to 1.4.0-2.0.1
aardvark-dns - update to 1.10.0-2.0.1
netavark - update to 1.10.3-1.0.1
fuse-overlayfs - update to 1.13-1.0.1
crun - update to 1.14.3-2
skopeo-tests - update to 1.14.3-2.0.1
skopeo - update to 1.14.3-2.0.1
python-urllib3 - update to 1.23-3.25.1
buildah - update to 1.33.7-1
buildah-tests - update to 1.33.7-1
containers-common - update to 1-81.0.1
conmon - update to 2.1.10-1
container-selinux - update to 2.229.0-2
python3-criu - update to 3.18-5.0.1
crit - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
libslirp-devel - update to 4.4.0-2
libslirp - update to 4.4.0-2
Platform Automation Toolkit - addressed in versions 4.4.19, 5.0.13
python3-podman - update to 4.9.0-1
podman - update to 4.9.4-1.0.1
podman-catatonit - update to 4.9.4-1.0.1
podman-gvproxy - update to 4.9.4-1.0.1
podman-plugins - update to 4.9.4-1.0.1
podman-remote - update to 4.9.4-1.0.1
podman-tests - update to 4.9.4-1.0.1
podman-docker - update to 4.9.4-1.0.1
IBM Spectrum Symphony - update to 7.3.2 Fix 601860
IBM Security Verify Access - update to 10.0.9
python3-pip-whl (Ubuntu package) - addressed in versions 22.0.2+dfsg-1ubuntu0.4, 23.0.1+dfsg-1ubuntu0.2, 23.2+dfsg-1ubuntu0.1
cockpit-podman - update to 84.1-1
External References
Related Security Bulletins
- Credentials disclosure via redirects in urllib3
- Ubuntu update for python-urllib3
- SUSE update for python-urllib3
- Ubuntu update for python-pip
- VMware Tanzu Platform Automation Toolkit update for pip
- Multiple vulnerabilities in IBM Spectrum Symphony
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- Multiple vulnerabilities in Dell Networking OS10
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Multiple vulnerabilities in Dell SmartFabric OS10
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in IBM Security Verify Access
- Anolis OS update for container-tools:an8 module
- PowerProtect Data Protection software update for third-party components
- Dell RecoverPoint for Virtual Machines update for third-party components