CVE-2023-32681
MediumAdvisory
Published 22 May 2023In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.1
- base score, highest
- EPSS
- 0.030
- 86th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 478
- of 17,787 indexed, latest versions
- Container images
- 509
- deployed by those charts
- Fix available
- 11 of 11
- affected packages
Unintended leak of Proxy-Authorization header in requests
Carried by container images the latest versions of 478 of 17,787 indexed charts deploy, on 509 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| requestspypi | 2.6.0, 2.9.1, 2.10.0, 2.11.1+20 more | 2.31.0 | 483 |
| requestsdeb | 2.2.1-1, 2.2.1-1ubuntu0.3, 2.9.1-3, 2.9.1-3ubuntu0.1+5 more | 2.2.1-1ubuntu0.4+esm1, 2.9.1-3ubuntu0.1+esm1, 2.18.4-2ubuntu0.1+esm1, 2.21.0-1+deb10u1+2 more | 51 |
| python-chardetrpm | 3.0.4-7.el8 | 0:3.0.4-10.module+el8.9.0+19487+7dc18407 | 44 |
| python-pysocksrpm | 1.6.8-3.el8 | 0:1.6.8-6.module+el8.9.0+19487+7dc18407 | 44 |
| python-idnarpm | 2.5-5.el8, 2.5-7.el8_10 | 0:2.5-7.module+el8.9.0+19487+7dc18407 | 43 |
| python-pipdeb | 20.0.2-5ubuntu1.1, 20.0.2-5ubuntu1.5, 20.0.2-5ubuntu1.6, 20.0.2-5ubuntu1.8+6 more | 20.0.2-5ubuntu1.9, 22.0.2+dfsg-1ubuntu0.7 | 42 |
| python-requestsrpm | 2.20.0-2.1.el8_1, 2.20.0-3.el8_6, 2.20.0-3.el8_8 | 0:2.20.0-3.el8_8, 0:2.20.0-4.module+el8.9.0+19487+7dc18407 | 34 |
| python2rpm | 2.7.17-2.module+el8.3.0+7681+f1f02ded, 2.7.18-4.module+el8.4.0+9577+0b56c8de | 0:2.7.18-15.module+el8.9.0+20125+68111a8f | 2 |
| python2-piprpm | 9.0.3-18.module+el8.3.0+7707+eb4bba01 | 0:9.0.3-19.module+el8.9.0+19487+7dc18407 | 2 |
| python2-setuptoolsrpm | 39.0.1-12.module+el8.3.0+7075+8484f0d0, 39.0.1-13.module+el8.4.0+9442+27d0e81c | 0:39.0.1-13.module+el8.9.0+19487+7dc18407 | 2 |
| python-wheelrpm | 1:0.31.1-2.module+el8.1.0+3724+3c097090 | 1:0.31.1-3.module+el8.9.0+19487+7dc18407 | 1 |
- OSV records
- DEBIAN-CVE-2023-32681GHSA-j8r2-6x86-q33qRHSA-2023:4520RHSA-2023:7042UBUNTU-CVE-2023-32681DLA-3456-1
- Also known as
- PYSEC-2023-74, RHSA-2024:0299, USN-6155-1, USN-6155-2, USN-7568-1, USN-7762-1
Charts affected
478 by stars
Container images carrying it
509 by charts deploying them
A fixed version is listed for 11 of the 11 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | 5d934bb66884 | python-chardet python-idna python-pysocks requests | 0:3.0.4-10.module+el8.9.0+19487+7dc18407 0:2.5-7.module+el8.9.0+19487+7dc18407 0:1.6.8-6.module+el8.9.0+19487+7dc18407 2.31.0 | 1 |
| quay.io/ | 59fe607dfdf2 | requests | 2.31.0 | 1 |
| quay.io/ | 7b4202c25b67 | requests | 2.31.0 | 1 |
| quay.io/ | 6ba82beff18e | python-chardet python-idna python-pysocks python-requests requests | 0:3.0.4-10.module+el8.9.0+19487+7dc18407 0:2.5-7.module+el8.9.0+19487+7dc18407 0:1.6.8-6.module+el8.9.0+19487+7dc18407 0:2.20.0-3.el8_8 2.31.0 | 1 |
| registry.gitlab.com/ | cf72810d33f5 | python-chardet python-idna python-pysocks python-requests requests | 0:3.0.4-10.module+el8.9.0+19487+7dc18407 0:2.5-7.module+el8.9.0+19487+7dc18407 0:1.6.8-6.module+el8.9.0+19487+7dc18407 0:2.20.0-3.el8_8 2.31.0 | 1 |
| registry.gitlab.com/ | f6385712935f | python-pip | 20.0.2-5ubuntu1.9 | 1 |
| registry.gitlab.com/ | 4eaf9c911f33 | requests | 2.31.0 | 1 |
| registry.gitlab.com/ | 0886cbbc5f95 | requests | 2.31.0 | 1 |
| registry.gitlab.com/ | fcf07d5ff7e2 | requests | 2.31.0 | 1 |