CVE-2024-37891: Proxy-Authorization request header isn't stripped during cross-origin redirects in urllib3
Last updated 31 October 2024
Other sources
Proxy-Authorization request header isn't stripped during cross-origin redirects in urllib3
— Microsoft
urllib3 is a user-friendly HTTP client library for Python. When using urllib3's proxy support with ProxyManager, the Proxy-Authorization header is only sent to the configured proxy, as expected. However, when sending HTTP requests without using urllib3's proxy support, it's possible to accidentally configure the Proxy-Authorization header even though it won't have any effect as the request is not using a forwarding proxy or a tunneling proxy. In those cases, urllib3 doesn't treat the Proxy-Authorization HTTP header as one carrying authentication material and thus doesn't strip the header on cross-origin redirects. Because this is a highly unlikely scenario, we believe the severity of this vulnerability is low for almost all users. Out of an abundance of caution urllib3 will automatically strip the Proxy-Authorization header during cross-origin redirects to avoid the small chance that users are doing this on accident. Users should use urllib3's proxy support or disable automatic redirects to achieve safe processing of the Proxy-Authorization header, but we still decided to strip the header by default in order to further protect users who aren't using the correct approach. We believe the number of usages affected by this advisory is low. It requires all of the following to be true to be exploited: 1. Setting the Proxy-Authorization header without using urllib3's built-in proxy support. 2. Not disabling HTTP redirects. 3. Either not using an HTTPS origin server or for the proxy or target origin to redirect to a malicious origin. Users are advised to update to either version 1.26.19 or version 2.2.2. Users unable to upgrade may use the Proxy-Authorization header with urllib3's ProxyManager, disable HTTP redirects using redirects=False when sending requests, or not user the Proxy-Authorization header as mitigations.
— Launchpad
urllib3 is a user-friendly HTTP client library for Python. When using urllib3's proxy support with ProxyManager, the Proxy-Authorization header is only sent to the configured proxy, as expected. However, when sending HTTP requests without using urllib3's proxy support, it's possible to accidentally configure the Proxy-Authorization header even though it won't have any effect as the request is not using a forwarding proxy or a tunneling proxy. In those cases, urllib3 doesn't treat the Proxy-Authorization HTTP header as one carrying authentication material and thus doesn't strip the header on cross-origin redirects.
Because this is a highly unlikely scenario, we believe the severity of this vulnerability is low for almost all users. Out of an abundance of caution urllib3 will automatically strip the Proxy-Authorization header during cross-origin redirects to avoid the small chance that users are doing this on accident. Users should use urllib3's proxy support or disable automatic redirects to achieve safe processing of the Proxy-Authorization header, but we still decided to strip the header by default in order to further protect users who aren't using the correct approach.
We believe the number of usages affected by this advisory is low. It requires all of the following to be true to be exploited: 1. Setting the Proxy-Authorization header without using urllib3's built-in proxy support. 2. Not disabling HTTP redirects. 3. Either not using an HTTPS origin server or for the proxy or target origin to redirect to a malicious origin. Users are advised to update to either version 1.26.19 or version 2.2.2. Users unable to upgrade may use the Proxy-Authorization header with urllib3's ProxyManager, disable HTTP redirects using redirects=False when sending requests, or not user the Proxy-Authorization header as mitigations.
https://github.com/urllib3/urllib3/commit/accff72ecc2f6cf5a76d9570198a93ac7c90270e https://github.com/urllib3/urllib3/security/advisories/GHSA-34jh-p97f-mpxf
— Red Hat
When using urllib3's proxy support with ProxyManager, the Proxy-Authorization header is only sent to the configured proxy, as expected.
However, when sending HTTP requests without using urllib3's proxy support, it's possible to accidentally configure the Proxy-Authorization header even though it won't have any effect as the request is not using a forwarding proxy or a tunneling proxy. In those cases, urllib3 doesn't treat the Proxy-Authorization HTTP header as one carrying authentication material and thus doesn't strip the header on cross-origin redirects.
Because this is a highly unlikely scenario, we believe the severity of this vulnerability is low for almost all users. Out of an abundance of caution urllib3 will automatically strip the Proxy-Authorization header during cross-origin redirects to avoid the small chance that users are doing this on accident.
Users should use urllib3's proxy support or disable automatic redirects to achieve safe processing of the Proxy-Authorization header, but we still decided to strip the header by default in order to further protect users who aren't using the correct approach.
Affected usages
We believe the number of usages affected by this advisory is low. It requires all of the following to be true to be exploited:
Setting the Proxy-Authorization header without using urllib3's built-in proxy support. Not disabling HTTP redirects. Either not using an HTTPS origin server or for the proxy or target origin to redirect to a malicious origin.
Remediation
Using the Proxy-Authorization header with urllib3's ProxyManager. Disabling HTTP redirects using redirects=False when sending requests. Not using the Proxy-Authorization header.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/urllib3to a version that resolves this vulnerability.Fixed in 2.2.2 - Upgrade
Upgrade
pip/urllib3to a version that resolves this vulnerability.Fixed in 1.26.19 - Upgrade
Upgrade
debian/python-urllib3to a version that resolves this vulnerability.Fixed in 1.26.5-1~exp1+deb11u1Fixed in 1.26.12-1+deb12u1Fixed in 2.3.0-1 - Upgrade
Upgrade
redhat/urllib3to a version that resolves this vulnerability.Fixed in 1.26.19 - Upgrade
Upgrade
redhat/urllib3to a version that resolves this vulnerability.Fixed in 2.2.2 - Upgrade
Upgrade
urllib3to a version that resolves this vulnerability.Fixed in 1.26.19 - Upgrade
Upgrade
urllib3to a version that resolves this vulnerability.Fixed in 2.2.2 - Configuration
When sending HTTP requests, disable automatic redirects by setting redirects=False so urllib3 safely processes the Proxy-Authorization header.
urllib3 redirects = False - Configuration
Do not use the Proxy-Authorization header if you are not using urllib3's built-in proxy support (or if you cannot upgrade), to avoid it being preserved during cross-origin redirects.
urllib3 Proxy-Authorization header usage = Do not set/use it - Configuration
When using a proxy, use urllib3's built-in proxy support (ProxyManager) so the Proxy-Authorization header is only sent to the configured proxy as expected.
urllib3 proxy authentication approach = Use urllib3 ProxyManager proxy support - Compensating control
If you cannot upgrade immediately, avoid conditions that allow Proxy-Authorization to persist across cross-origin redirects: ensure you disable automatic redirects (redirects=False) and/or use urllib3's proxy support (ProxyManager) instead of setting Proxy-Authorization without proxy support.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37891?
CVE-2024-37891 has been classified as a medium severity vulnerability.
How do I fix CVE-2024-37891?
To fix CVE-2024-37891, upgrade urllib3 to version 1.26.19 or 2.2.2.
What does CVE-2024-37891 affect?
CVE-2024-37891 affects the urllib3 HTTP client library used in various packages and products.
Can CVE-2024-37891 be exploited?
Yes, CVE-2024-37891 can be exploited by attackers to compromise the confidentiality of the proxy authorization headers.
Which versions of urllib3 are vulnerable to CVE-2024-37891?
Versions of urllib3 prior to 1.26.19 and 2.2.2 are vulnerable to CVE-2024-37891.