目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2023-45803— urllib3 信息泄露漏洞

一分钟漏洞结论

影响对象
urllib3 urllib3
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

urllib3是一款Python HTTP库。该产品具有线程安全连接池、文件发布支持等。 urllib3存在安全漏洞,该漏洞源于从303状态更改请求方法重定向到GET后不会删除请求正文。受影响的产品和版本:urllib3 2至2.0.6版本,1.26.17及之前版本。

CVSS 4.2 · Medium EPSS 0.54% · P43

可能的 ATT&CK 技术 1 AI

T1557 · Adversary-in-the-Middle
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2023-45803 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Request body not stripped after redirect in urllib3
来源: CVE Program / CVE List V5
Vulnerability Description
urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had its method changed from one that could accept a request body (like `POST`) to `GET` as is required by HTTP RFCs. Although this behavior is not specified in the section for redirects, it can be inferred by piecing together information from different sections and we have observed the behavior in other major HTTP client implementations like curl and web browsers. Because the vulnerability requires a previously trusted service to become compromised in order to have an impact on confidentiality we believe the exploitability of this vulnerability is low. Additionally, many users aren't putting sensitive data in HTTP request bodies, if this is the case then this vulnerability isn't exploitable. Both of the following conditions must be true to be affected by this vulnerability: 1. Using urllib3 and submitting sensitive information in the HTTP request body (such as form data or JSON) and 2. The origin service is compromised and starts redirecting using 301, 302, or 303 to a malicious peer or the redirected-to service becomes compromised. This issue has been addressed in versions 1.26.18 and 2.0.7 and users are advised to update to resolve this issue. Users unable to update should disable redirects for services that aren't expecting to respond with redirects with `redirects=False` and disable automatic redirects with `redirects=False` and handle 301, 302, and 303 redirects manually by stripping the HTTP request body.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
信息暴露
来源: CVE Program / CVE List V5
Vulnerability Title
urllib3 信息泄露漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
urllib3是一款Python HTTP库。该产品具有线程安全连接池、文件发布支持等。 urllib3存在安全漏洞,该漏洞源于从303状态更改请求方法重定向到GET后不会删除请求正文。受影响的产品和版本:urllib3 2至2.0.6版本,1.26.17及之前版本。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
urllib3 urllib3 >= 2.0.0, < 2.0.7 -

二、漏洞 CVE-2023-45803 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2023-45803 的情报信息

请登录查看更多情报信息。

CVE-2023-45803 补丁与修复 (1)

CVE-2023-45803 厂商安全公告 (1)

CVE-2023-45803 邮件列表归档 (3)

CVE-2023-45803 其他参考 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2023-45803

暂无评论


发表评论