USN-7084-2: pip vulnerability
USN-7084-2: pip vulnerability
30 October 2024
urllib3 could leak sensitive information.
Releases
Ubuntu 24.10 Ubuntu 24.04 LTS Ubuntu 22.04 LTS Ubuntu 20.04 LTS Ubuntu 18.04 ESM Ubuntu 16.04 ESM
Packages
python-pip - Python package installer
Details
USN-7084-1 fixed vulnerability in urllib3. This update provides the
corresponding update for the urllib3 module bundled into pip.
Original advisory details:
It was discovered that urllib3 didn’t strip HTTP Proxy-Authorization
header on cross-origin redirects. A remote attacker could possibly use
this issue to obtain sensitive information.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.10
python3-pip - 24.2+dfsg-1ubuntu0.1
python3-pip-whl - 24.2+dfsg-1ubuntu0.1
Ubuntu 24.04
python3-pip - 24.0+dfsg-1ubuntu1.1
python3-pip-whl - 24.0+dfsg-1ubuntu1.1
Ubuntu 22.04
python3-pip - 22.0.2+dfsg-1ubuntu0.5
python3-pip-whl - 22.0.2+dfsg-1ubuntu0.5