Vulnerability Description
urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly. This issue has been patched in urllib3 version 1.26.17 or 2.0.5.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Python | Urllib3 | < 1.26.17 |
| Debian | Debian Linux | 10.0 |
| Fedoraproject | Fedora | 37 |
Related Weaknesses (CWE)
References
- https://github.com/urllib3/urllib3/commit/01220354d389cd05474713f8c982d05c9b17aaPatch
- https://github.com/urllib3/urllib3/commit/644124ecd0b6e417c527191f866daa05a5a205Patch
- https://github.com/urllib3/urllib3/security/advisories/GHSA-v845-jxx5-vc9fPatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00012.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing ListThird Party Advisory
- https://github.com/urllib3/urllib3/commit/01220354d389cd05474713f8c982d05c9b17aaPatch
- https://github.com/urllib3/urllib3/commit/644124ecd0b6e417c527191f866daa05a5a205Patch
- https://github.com/urllib3/urllib3/security/advisories/GHSA-v845-jxx5-vc9fPatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00012.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/12/msg00020.html
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing ListThird Party Advisory
FAQ
What is CVE-2023-43804?
CVE-2023-43804 is a vulnerability with a CVSS score of 5.9 (MEDIUM). urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of t...
How severe is CVE-2023-43804?
CVE-2023-43804 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-43804?
Check the references section above for vendor advisories and patch information. Affected products include: Python Urllib3, Debian Debian Linux, Fedoraproject Fedora.