VYPR

PyPI package

urllib3

pkg:pypi/urllib3

Vulnerabilities (22)

  • CVE-2018-20060CriDec 11, 2018
    affected < 1.23fixed 1.23

    urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted i

  • CVE-2016-9015LowJan 11, 2017
    affected >= 1.17, < 1.18.1fixed 1.18.1

    Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS certificates. This places users of the library with those configurations at risk of man-in-the-middle and information lea

Page 2 of 2