Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-35678

Опубликовано: 18 дек. 2020
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

Autobahn|Python before 20.12.3 allows redirect header injection.

A flaw was found in python-autobahn, where it allows redirect header injection. The highest threat from this vulnerability is to confidentiality and integrity.

Отчет

In Red Hat OpenStack Platform, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP python-autobahn package.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 1.2autobahnAffected
Red Hat OpenStack Platform 10 (Newton)python-autobahnOut of support scope
Red Hat OpenStack Platform 13 (Queens)python-autobahnWill not fix
Red Hat OpenStack Platform 16.1python-autobahnWill not fix
Red Hat Quay 3quayWill not fix
Red Hat Ansible Tower 3.6 for RHEL 7ansible-tower-36/ansible-towerFixedRHSA-2021:077809.03.2021
Red Hat Ansible Tower 3.7 for RHEL 7ansible-tower-37/ansible-tower-rhel7FixedRHSA-2021:077909.03.2021
Red Hat Ansible Tower 3.8 for RHEL 7ansible-tower-38/ansible-runner-rhel7FixedRHSA-2021:078009.03.2021
Red Hat Ansible Tower 3.8 for RHEL 7ansible-tower-38/ansible-tower-rhel7FixedRHSA-2021:078009.03.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=1911314python-autobahn: allows redirect header injection

EPSS

Процентиль: 52%
0.00294
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 5 лет назад

Autobahn|Python before 20.12.3 allows redirect header injection.

CVSS3: 6.1
nvd
около 5 лет назад

Autobahn|Python before 20.12.3 allows redirect header injection.

CVSS3: 6.1
debian
около 5 лет назад

Autobahn|Python before 20.12.3 allows redirect header injection.

suse-cvrf
около 5 лет назад

Security update for python-autobahn

suse-cvrf
около 5 лет назад

Security update for python-autobahn

EPSS

Процентиль: 52%
0.00294
Низкий

6.1 Medium

CVSS3