Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Debian 11: DLA-3998-1 critical: python-urllib3 authorization bypass

debian lts
Calendar Grey December 21, 2024
Scroller Debian Lts
Explore security flaws within python-urllib3 as outlined in Debian LTS Advisory DLA-3998-1. Understand the remedies and enhancements available.
Multiple vulnerabilities were found in python-urllib3, an HTTP library with thread-safe connection pooling for Python, which could lead to information disclosure or authorization b...

Summary

CVE-2023-43804

It was discovered that the cookie request header wasn't stripped
during cross-origin redirects. It is therefore possible for a user
to specify a Cookie header and unknowingly leak information via HTTP
redirects to a different origin if redirection isn't explicitly
disabled.

CVE-2023-45803

It was discovered that the request body wasn't stripped when an HTTP
redirect response using status 303 "See Other", after the request
had its method changed from one that could accept a request body
(like POST) to GET as is required by HTTP RFCs.

CVE-2024-37891

It was discovered that the Proxy-Authorization request header isn't
stripped during cross-origin redirects, when urllib3 is used without
proxy support.

For Debian 11 bullseye, these problems have been fixed in version
1.26.5-1~exp1+deb11u1.

We recommend that you upgrade your python-urllib3 packages.

For the detailed security status of python-urllib3 please refer to
its security tracker page at:

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: python-urllib3
Version: 1.26.5-1~exp1+deb11u1
CVE ID: CVE-2023-43804 CVE-2023-45803 CVE-2024-37891
Debian Bug: 1053626 1054226 1074149 1089507

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.