VDB

ALSA-2024%3A6162

ALSA-2024%3A6162 PUBLISHED

The python-urllib3 package provides the Python HTTP module with connection pooling and file POST abilities. Security Fix(es): * urllib3: proxy-authorization request header is not stripped during cross-origin redirects (CVE-2024-37891) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected Products

VendorProductVersions
AlmaLinux:9python3-urllib30, 0

Timeline

  • Sep 3, 2024 CVE Published
  • Sep 3, 2024 CVE Updated
  • Mar 6, 2026 Distribution Patch
  • Mar 6, 2026 Distribution Patch
  • Mar 6, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›