Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-11078

Опубликовано: 20 мая 2020
Источник: ubuntu
Приоритет: low
CVSS2: 4.3
CVSS3: 6.8

Описание

In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for httplib2.Http.request() could change request headers and body, send additional hidden requests to same server. This vulnerability impacts software that uses httplib2 with uri constructed by string concatenation, as opposed to proper urllib building with escaping. This has been fixed in 0.18.0.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

0.18.1-1
eoan

ignored

end of life
esm-infra-legacy/trusty

needed

esm-infra/bionic

needed

esm-infra/focal

needed

esm-infra/xenial

needed

focal

ignored

end of standard support, was needed
groovy

not-affected

0.18.1-1
hirsute

not-affected

0.18.1-1

Показывать по

4.3 Medium

CVSS2

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
redhat
больше 5 лет назад

In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability impacts software that uses httplib2 with uri constructed by string concatenation, as opposed to proper urllib building with escaping. This has been fixed in 0.18.0.

CVSS3: 6.8
nvd
больше 5 лет назад

In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability impacts software that uses httplib2 with uri constructed by string concatenation, as opposed to proper urllib building with escaping. This has been fixed in 0.18.0.

CVSS3: 6.8
debian
больше 5 лет назад

In httplib2 before version 0.18.0, an attacker controlling unescaped p ...

CVSS3: 6.8
github
больше 5 лет назад

CRLF injection in httplib2

oracle-oval
около 5 лет назад

ELSA-2020-5947: resource-agents security update (IMPORTANT)

4.3 Medium

CVSS2

6.8 Medium

CVSS3