Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mfrc-633m-gcwg

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.

CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.

EPSS

Процентиль: 93%
0.10221
Средний

6.1 Medium

CVSS3

Дефекты

CWE-113

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 9 лет назад

CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.

CVSS3: 5.3
redhat
больше 10 лет назад

CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.

CVSS3: 6.1
nvd
почти 9 лет назад

CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.

CVSS3: 6.1
debian
почти 9 лет назад

CRLF injection vulnerability in the HTTPConnection.putheader function ...

suse-cvrf
почти 9 лет назад

Security update for python

EPSS

Процентиль: 93%
0.10221
Средний

6.1 Medium

CVSS3

Дефекты

CWE-113