Описание
In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.
Отчет
This issue affects the version of python-urllib3 shipped with Red Hat Gluster Storage 3, as it is vulnerable to CRLF injection. Red Hat Satellite 6.2 is on Maintenance Support 2 phase, hence only selected critical and important issues will be fixed. Please refer to Red Hat Satellite Product Life Cycle page for more information. In Red Hat OpenStack Platform 13, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP python-urllib3 package.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | python-urllib3 | Will not fix | ||
Red Hat Enterprise Linux 8 | python36:3.6/python-virtualenv | Not affected | ||
Red Hat OpenShift Container Platform 3.10 | python-urllib3 | Out of support scope | ||
Red Hat OpenShift Container Platform 3.11 | python-urllib3 | Will not fix | ||
Red Hat OpenShift Container Platform 3.6 | python-urllib3 | Out of support scope | ||
Red Hat OpenShift Container Platform 3.7 | python-urllib3 | Out of support scope | ||
Red Hat OpenShift Container Platform 3.9 | python-urllib3 | Out of support scope | ||
Red Hat OpenStack Platform 10 (Newton) | python-urllib3 | Will not fix | ||
Red Hat OpenStack Platform 13 (Queens) | python-urllib3 | Will not fix | ||
Red Hat OpenStack Platform 14 (Rocky) | python-urllib3 | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.
In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.
In the urllib3 library through 1.24.1 for Python, CRLF injection is po ...
Improper Neutralization of CRLF Sequences in urllib3 library for Python
EPSS
6.5 Medium
CVSS3