New Debian python-urllib3 1.24.1-1+deb10u3 fixes: This update addresses the following issue: 1.24.1-1+deb10u3 (Thu, 20 Feb 2025 13:18:31 +0100) * Non-maintainer upload by the ELTS Team. * Fix CVE-2024-37891: Proxy-Authorization request header isn't stripped during cross-origin redirects.
--- mirror/ftp/pool/main/p/python-urllib3/python-urllib3_1.24.1-1+deb10u2.dsc +++ apt/ucs_5.0-0-errata5.0-9/source/python-urllib3_1.24.1-1+deb10u3.dsc @@ -1,3 +1,9 @@ +1.24.1-1+deb10u3 [Thu, 20 Feb 2025 13:18:31 +0100] Guilhem Moulin <guilhem@debian.org>: + + * Non-maintainer upload by the ELTS Team. + * Fix CVE-2024-37891: Proxy-Authorization request header isn't stripped + during cross-origin redirects. (Closes: #1074149) + 1.24.1-1+deb10u2 [Wed, 08 Nov 2023 11:02:05 +0000] Sean Whitton <spwhitton@spwhitton.name>: [ Sean Whitton ] <http://piuparts.knut.univention.de/5.0-9/#6066590953850139703>
OK: piuparts OK: automated tests
<https://errata.software-univention.de/#/?erratum=5.0x1219>