Safety vulnerability ID: 36762
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Kubernetes 7.0.1, 8.0.1 and 9.0.0a1 include a fix for CVE-2018-20060: urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.
Latest version: 31.0.0
Kubernetes python client
**Security Fix:**
- Bump urllib3 version to pick up security fix for CVE-2018-20060 [kubernetes-client/python707](https://github.com/kubernetes-client/python/pull/707)
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application