`Cookie` HTTP header isn't stripped on cross-origin redirects
CVE-2023-43804
Key Information:
Badges
What is CVE-2023-43804?
The urllib3 library, a widely used HTTP client for Python, exposes a security risk when users inadvertently include a Cookie header during HTTP requests. This oversight can lead to unintentional information leakage through HTTP redirects, especially when redirect behavior is not explicitly managed. Users must ensure they disable automatic redirects to mitigate this risk. The issue has been addressed in versions 1.26.17 and 2.0.5, emphasizing the importance of keeping library dependencies updated.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
urllib3 >= 2.0.0, < 2.0.6 < 2.0.0, 2.0.6
urllib3 < 1.26.17 < 1.26.17
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
