Описание
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
A flaw was found in python-urllib3. The HTTPConnection.request() does not properly validate CRLF sequences in the HTTP request method, potentially allowing manipulation of the request by injecting additional HTTP headers. The highest threat from this vulnerability is to confidentiality and integrity.
Отчет
- Red Hat OpenShift Container Platform (OCP) 4 delivers the python-urllib3 package, which includes a vulnerable version of the urllib3 module, however from OCP 4.6, the python-urllib3 package is no longer shipped and will not be fixed.
- In Red Hat OpenStack Platform, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP python-urllib3 package.
Note: Versions of
python-pip
are marked as not affected because there is no way for a pip user to control the HTTP request method.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | python-urllib3 | Out of support scope | ||
Red Hat Enterprise Linux 7 | python-pip | Not affected | ||
Red Hat Enterprise Linux 8 | python38:3.8/python3x-pip | Not affected | ||
Red Hat Enterprise Linux 8 | python38:3.8/python-urllib3 | Not affected | ||
Red Hat Enterprise Linux 8 | python-pip | Not affected | ||
Red Hat OpenStack Platform 10 (Newton) | python-urllib3 | Out of support scope | ||
Red Hat OpenStack Platform 13 (Queens) | python-urllib3 | Will not fix | ||
Red Hat Software Collections | python27-python-pip | Not affected | ||
Red Hat Software Collections | rh-mongodb36-python-urllib3 | Will not fix | ||
Red Hat Software Collections | rh-python36-python-pip | Not affected |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
urllib3 before 1.25.9 allows CRLF injection if the attacker controls t ...
Security update for aws-cli, python-boto3, python-botocore, python-service_identity, python-trustme, python-urllib3
6.5 Medium
CVSS3