CVE-2023-43804

Updated: 2025-11-10 00:30:35.877225

Description:

urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly. This issue has been patched in urllib3 version 1.26.17 or 2.0.5.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 8.1

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU python3 3.9.16 8.1 HIGH Not Vulnerable 2025-02-21 11:37:28
AlmaLinux 9.2 ESU python3.11-urllib3 1.26.12 8.1 HIGH Released CLSA-2025:1763032859 2025-11-13 16:17:51
CentOS 8.4 ELS python3 3.6.8 8.1 HIGH Not Vulnerable 2025-02-20 06:37:51
CentOS 8.4 ELS python2 2.7.18 8.1 HIGH Not Vulnerable 2025-02-20 11:32:31
CentOS 8.5 ELS python2 2.7.18 8.1 HIGH Not Vulnerable 2025-02-20 11:32:31
CentOS 8.5 ELS python3 3.6.8 8.1 HIGH Not Vulnerable 2025-02-20 06:37:51
Ubuntu 16.04 ELS python2.7 2.7.12 8.1 HIGH Not Vulnerable 2025-02-20 11:32:31
Ubuntu 18.04 ELS python2.7 2.7.17-1 8.1 HIGH Not Vulnerable 2025-02-20 11:32:31