Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2021-1631

Опубликовано: 25 мая 2021
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2021-1631: python-urllib3 security update (MODERATE)

[1.24.2-5.0.1]

  • set RECENT_DATE to 01/30/2019 to make checks happy [Orabug: 30228991]

[1.24.2-5]

  • Security fix for CVE-2020-26137 Resolves: rhbz#1883889

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

python3-urllib3

1.24.2-5.0.1.el8

Oracle Linux x86_64

python3-urllib3

1.24.2-5.0.1.el8

Связанные CVE

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 4 лет назад

urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.

CVSS3: 6.5
redhat
больше 5 лет назад

urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.

CVSS3: 6.5
nvd
больше 4 лет назад

urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.

CVSS3: 6.5
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 6.5
debian
больше 4 лет назад

urllib3 before 1.25.9 allows CRLF injection if the attacker controls t ...