[RHSA-2024:0464] python-urllib3 security update

Severity Moderate
Affected Packages 1
CVEs 2

The python-urllib3 package provides the Python HTTP module with connection pooling and file POST abilities.

Security Fix(es):

  • python-urllib3: Cookie request header isn't stripped during cross-origin redirects (CVE-2023-43804)

  • urllib3: Request body not stripped after redirect from 303 status changes request method to GET (CVE-2023-45803)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Package Affected Version
pkg:rpm/redhat/python3-urllib3?distro=redhat-9.3 < 1.26.5-3.el9_3.1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/redhat/python3-urllib3?distro=redhat-9.3 redhat python3-urllib3 < 1.26.5-3.el9_3.1 redhat-9.3
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...