<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for python-urllib3</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2024:2879-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2024-08-12T13:19:48Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-08-12T13:19:48Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-08-12T13:19:48Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for python-urllib3</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for python-urllib3 fixes the following issues:

- CVE-2024-37891: Fixed proxy-authorization request header is not stripped during cross-origin redirects (bsc#1226469)
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">Image SLES12-SP5-Azure-BYOS-2024-2879,Image SLES12-SP5-Azure-HPC-BYOS-2024-2879,Image SLES12-SP5-Azure-HPC-On-Demand-2024-2879,Image SLES12-SP5-Azure-SAP-BYOS-2024-2879,Image SLES12-SP5-Azure-SAP-On-Demand-2024-2879,Image SLES12-SP5-Azure-Standard-On-Demand-2024-2879,Image SLES12-SP5-EC2-BYOS-2024-2879,Image SLES12-SP5-EC2-ECS-On-Demand-2024-2879,Image SLES12-SP5-EC2-On-Demand-2024-2879,Image SLES12-SP5-EC2-SAP-BYOS-2024-2879,Image SLES12-SP5-EC2-SAP-On-Demand-2024-2879,Image SLES12-SP5-GCE-BYOS-2024-2879,Image SLES12-SP5-GCE-On-Demand-2024-2879,Image SLES12-SP5-GCE-SAP-BYOS-2024-2879,Image SLES12-SP5-GCE-SAP-On-Demand-2024-2879,Image SLES12-SP5-SAP-Azure-LI-BYOS-Production-2024-2879,Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production-2024-2879,SUSE-2024-2879,SUSE-SLE-Module-Public-Cloud-12-2024-2879,SUSE-SLE-SDK-12-SP5-2024-2879,SUSE-SLE-SERVER-12-SP5-2024-2879,SUSE-SLE-WE-12-SP5-2024-2879</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20242879-1/</URL>
      <Description>Link for SUSE-SU-2024:2879-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-updates/2024-August/036411.html</URL>
      <Description>E-Mail link for SUSE-SU-2024:2879-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1226469</URL>
      <Description>SUSE Bug 1226469</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-37891/</URL>
      <Description>SUSE CVE CVE-2024-37891 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="Image SLES12-SP5-Azure-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-Azure-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-Azure-BYOS">Image SLES12-SP5-Azure-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-Azure-HPC-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-Azure-HPC-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-Azure-HPC-BYOS">Image SLES12-SP5-Azure-HPC-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-Azure-HPC-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-Azure-HPC-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-Azure-HPC-On-Demand">Image SLES12-SP5-Azure-HPC-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-Azure-SAP-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-Azure-SAP-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-Azure-SAP-BYOS">Image SLES12-SP5-Azure-SAP-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-Azure-SAP-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-Azure-SAP-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-Azure-SAP-On-Demand">Image SLES12-SP5-Azure-SAP-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-Azure-Standard-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-Azure-Standard-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-Azure-Standard-On-Demand">Image SLES12-SP5-Azure-Standard-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-EC2-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-EC2-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-EC2-BYOS">Image SLES12-SP5-EC2-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-EC2-ECS-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-EC2-ECS-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-EC2-ECS-On-Demand">Image SLES12-SP5-EC2-ECS-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-EC2-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-EC2-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-EC2-On-Demand">Image SLES12-SP5-EC2-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-EC2-SAP-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-EC2-SAP-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-EC2-SAP-BYOS">Image SLES12-SP5-EC2-SAP-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-EC2-SAP-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-EC2-SAP-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-EC2-SAP-On-Demand">Image SLES12-SP5-EC2-SAP-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-GCE-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-GCE-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-GCE-BYOS">Image SLES12-SP5-GCE-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-GCE-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-GCE-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-GCE-On-Demand">Image SLES12-SP5-GCE-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-GCE-SAP-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-GCE-SAP-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-GCE-SAP-BYOS">Image SLES12-SP5-GCE-SAP-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-GCE-SAP-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-GCE-SAP-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-GCE-SAP-On-Demand">Image SLES12-SP5-GCE-SAP-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production">
        <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production">Image SLES12-SP5-SAP-Azure-LI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production">
        <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production">Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Module for Public Cloud 12">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Public Cloud 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Public Cloud 12" CPE="cpe:/o:suse:sle-module-public-cloud:12">SUSE Linux Enterprise Module for Public Cloud 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP5">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5" CPE="cpe:/o:suse:sles:12:sp5">SUSE Linux Enterprise Server 12 SP5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5" CPE="cpe:/o:suse:sles_sap:12:sp5">SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Software Development Kit 12 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Software Development Kit 12 SP5">
        <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP5" CPE="cpe:/o:suse:sle-sdk:12:sp5">SUSE Linux Enterprise Software Development Kit 12 SP5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Workstation Extension 12 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Workstation Extension 12 SP5">
        <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 12 SP5" CPE="cpe:/o:suse:sle-we:12:sp5">SUSE Linux Enterprise Workstation Extension 12 SP5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="python-urllib3-1.25.10-3.40.1">
      <FullProductName ProductID="python-urllib3-1.25.10-3.40.1">python-urllib3-1.25.10-3.40.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-urllib3-1.25.10-3.40.1">
      <FullProductName ProductID="python3-urllib3-1.25.10-3.40.1">python3-urllib3-1.25.10-3.40.1</FullProductName>
    </Branch>
    <Relationship ProductReference="python-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-Azure-BYOS:python-urllib3-1.25.10-3.40.1">python-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-Azure-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-Azure-BYOS:python3-urllib3-1.25.10-3.40.1">python3-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-Azure-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-HPC-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-Azure-HPC-BYOS:python-urllib3-1.25.10-3.40.1">python-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-Azure-HPC-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-HPC-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-Azure-HPC-BYOS:python3-urllib3-1.25.10-3.40.1">python3-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-Azure-HPC-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-HPC-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-Azure-HPC-On-Demand:python3-urllib3-1.25.10-3.40.1">python3-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-Azure-HPC-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-SAP-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-Azure-SAP-BYOS:python-urllib3-1.25.10-3.40.1">python-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-Azure-SAP-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-SAP-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-Azure-SAP-BYOS:python3-urllib3-1.25.10-3.40.1">python3-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-Azure-SAP-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-SAP-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-Azure-SAP-On-Demand:python-urllib3-1.25.10-3.40.1">python-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-Azure-SAP-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-SAP-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-Azure-SAP-On-Demand:python3-urllib3-1.25.10-3.40.1">python3-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-Azure-SAP-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-Standard-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-Azure-Standard-On-Demand:python3-urllib3-1.25.10-3.40.1">python3-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-Azure-Standard-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-EC2-BYOS:python-urllib3-1.25.10-3.40.1">python-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-EC2-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-EC2-BYOS:python3-urllib3-1.25.10-3.40.1">python3-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-EC2-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-ECS-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-EC2-ECS-On-Demand:python-urllib3-1.25.10-3.40.1">python-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-EC2-ECS-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-ECS-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-EC2-ECS-On-Demand:python3-urllib3-1.25.10-3.40.1">python3-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-EC2-ECS-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-EC2-On-Demand:python-urllib3-1.25.10-3.40.1">python-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-EC2-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-EC2-On-Demand:python3-urllib3-1.25.10-3.40.1">python3-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-EC2-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-SAP-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-EC2-SAP-BYOS:python-urllib3-1.25.10-3.40.1">python-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-EC2-SAP-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-SAP-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-EC2-SAP-BYOS:python3-urllib3-1.25.10-3.40.1">python3-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-EC2-SAP-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-SAP-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-EC2-SAP-On-Demand:python-urllib3-1.25.10-3.40.1">python-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-EC2-SAP-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-SAP-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-EC2-SAP-On-Demand:python3-urllib3-1.25.10-3.40.1">python3-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-EC2-SAP-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-GCE-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-GCE-BYOS:python-urllib3-1.25.10-3.40.1">python-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-GCE-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-GCE-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-GCE-BYOS:python3-urllib3-1.25.10-3.40.1">python3-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-GCE-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-GCE-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-GCE-On-Demand:python3-urllib3-1.25.10-3.40.1">python3-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-GCE-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-GCE-SAP-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-GCE-SAP-BYOS:python-urllib3-1.25.10-3.40.1">python-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-GCE-SAP-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-GCE-SAP-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-GCE-SAP-BYOS:python3-urllib3-1.25.10-3.40.1">python3-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-GCE-SAP-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-GCE-SAP-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-GCE-SAP-On-Demand:python-urllib3-1.25.10-3.40.1">python-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-GCE-SAP-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-GCE-SAP-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-GCE-SAP-On-Demand:python3-urllib3-1.25.10-3.40.1">python3-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-GCE-SAP-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production">
      <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:python-urllib3-1.25.10-3.40.1">python-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-SAP-Azure-LI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production">
      <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:python-urllib3-1.25.10-3.40.1">python-urllib3-1.25.10-3.40.1 as a component of Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Public Cloud 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Public Cloud 12:python-urllib3-1.25.10-3.40.1">python-urllib3-1.25.10-3.40.1 as a component of SUSE Linux Enterprise Module for Public Cloud 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Public Cloud 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Public Cloud 12:python3-urllib3-1.25.10-3.40.1">python3-urllib3-1.25.10-3.40.1 as a component of SUSE Linux Enterprise Module for Public Cloud 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:python-urllib3-1.25.10-3.40.1">python-urllib3-1.25.10-3.40.1 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:python3-urllib3-1.25.10-3.40.1">python3-urllib3-1.25.10-3.40.1 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:python-urllib3-1.25.10-3.40.1">python-urllib3-1.25.10-3.40.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:python3-urllib3-1.25.10-3.40.1">python3-urllib3-1.25.10-3.40.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP5:python3-urllib3-1.25.10-3.40.1">python3-urllib3-1.25.10-3.40.1 as a component of SUSE Linux Enterprise Software Development Kit 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-urllib3-1.25.10-3.40.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 12 SP5:python3-urllib3-1.25.10-3.40.1">python3-urllib3-1.25.10-3.40.1 as a component of SUSE Linux Enterprise Workstation Extension 12 SP5</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en"> urllib3 is a user-friendly HTTP client library for Python. When using urllib3's proxy support with `ProxyManager`, the `Proxy-Authorization` header is only sent to the configured proxy, as expected. However, when sending HTTP requests *without* using urllib3's proxy support, it's possible to accidentally configure the `Proxy-Authorization` header even though it won't have any effect as the request is not using a forwarding proxy or a tunneling proxy. In those cases, urllib3 doesn't treat the `Proxy-Authorization` HTTP header as one carrying authentication material and thus doesn't strip the header on cross-origin redirects. Because this is a highly unlikely scenario, we believe the severity of this vulnerability is low for almost all users. Out of an abundance of caution urllib3 will automatically strip the `Proxy-Authorization` header during cross-origin redirects to avoid the small chance that users are doing this on accident. Users should use urllib3's proxy support or disable automatic redirects to achieve safe processing of the `Proxy-Authorization` header, but we still decided to strip the header by default in order to further protect users who aren't using the correct approach. We believe the number of usages affected by this advisory is low. It requires all of the following to be true to be exploited: 1. Setting the `Proxy-Authorization` header without using urllib3's built-in proxy support. 2. Not disabling HTTP redirects. 3. Either not using an HTTPS origin server or for the proxy or target origin to redirect to a malicious origin. Users are advised to update to either version 1.26.19 or version 2.2.2. Users unable to upgrade may use the `Proxy-Authorization` header with urllib3's `ProxyManager`, disable HTTP redirects using `redirects=False` when sending requests, or not user the `Proxy-Authorization` header as mitigations.</Note>
    </Notes>
    <CVE>CVE-2024-37891</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-Azure-BYOS:python-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-BYOS:python3-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-HPC-BYOS:python-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-HPC-BYOS:python3-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-HPC-On-Demand:python3-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-SAP-BYOS:python-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-SAP-BYOS:python3-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-SAP-On-Demand:python-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-SAP-On-Demand:python3-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-Standard-On-Demand:python3-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-BYOS:python-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-BYOS:python3-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:python-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:python3-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-On-Demand:python-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-On-Demand:python3-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-SAP-BYOS:python-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-SAP-BYOS:python3-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-SAP-On-Demand:python-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-SAP-On-Demand:python3-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-BYOS:python-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-BYOS:python3-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-On-Demand:python3-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-SAP-BYOS:python-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-SAP-BYOS:python3-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-SAP-On-Demand:python-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-SAP-On-Demand:python3-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:python-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:python-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Public Cloud 12:python-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Public Cloud 12:python3-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:python-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:python3-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:python-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:python3-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP5:python3-urllib3-1.25.10-3.40.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12 SP5:python3-urllib3-1.25.10-3.40.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20242879-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-37891.html</URL>
        <Description>CVE-2024-37891</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1226469</URL>
        <Description>SUSE Bug 1226469</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
