ELA-1761-1 python-urllib3 security update (by ) (opens in new tab)
Package : python-urllib3 Version : 1.19.1-1+deb9u5 (stretch), 1.24.1-1+deb10u6 (buster) Related CVEs : It was discovered that python-urllib3, did not strip out sensitive headers (such as Authorization or Cookie) during cross-origin redirects followed from the low-level API. The issue may lead to information disclosure or authorization bypass. The issue stems from an incomplete fix for CVE-2018-20060.
Read the original article