peter bassill · operator
$ cve CVE-2018-20060 JSON

CVE-2018-20060

9.8
CRITICAL · CVSS 3.0 · EPSS 4.5% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.49% — more likely to be exploited than 91% of all CVEs
On CISA KEVno
Public exploitnone known
Published2018-12-11
Last modified2026-06-17

Affected (2)

VendorProduct
fedoraprojectfedora
pythonurllib3

References

→ the Explorer  ·  watch your stack  ·  NVD