Описание
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 2.7.17-1~18.04ubuntu1.7 |
devel | DNE | |
esm-apps/focal | released | 2.7.18-1~20.04.4+esm1 |
esm-apps/jammy | released | 2.7.18-13ubuntu1.2+esm1 |
esm-infra-legacy/trusty | not-affected | 2.7.6-8ubuntu0.6+esm12 |
esm-infra/bionic | not-affected | 2.7.17-1~18.04ubuntu1.7 |
esm-infra/xenial | released | 2.7.12-1ubuntu0~16.04.18+esm1 |
focal | ignored | end of standard support, was needed |
impish | ignored | end of life |
jammy | needed |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
devel | DNE | |
esm-infra-legacy/trusty | DNE | |
esm-infra/focal | DNE | |
focal | DNE | |
impish | not-affected | |
jammy | not-affected | |
kinetic | not-affected | |
lunar | DNE | |
mantic | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
devel | DNE | |
esm-infra-legacy/trusty | not-affected | 3.4.3-1ubuntu1~14.04.7+esm12 |
esm-infra/focal | DNE | |
focal | DNE | |
impish | DNE | |
jammy | DNE | |
kinetic | DNE | |
lunar | DNE | |
mantic | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
devel | DNE | |
esm-infra-legacy/trusty | not-affected | 3.5.2-2ubuntu0~16.04.4~14.04.1+esm1 |
esm-infra/focal | DNE | |
esm-infra/xenial | released | 3.5.2-2ubuntu0~16.04.13+esm2 |
focal | DNE | |
impish | DNE | |
jammy | DNE | |
kinetic | DNE | |
lunar | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 3.6.9-1~18.04ubuntu1.7 |
devel | DNE | |
esm-infra-legacy/trusty | DNE | |
esm-infra/bionic | not-affected | 3.6.9-1~18.04ubuntu1.7 |
esm-infra/focal | DNE | |
focal | DNE | |
impish | DNE | |
jammy | DNE | |
kinetic | DNE | |
lunar | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support, was needed |
devel | DNE | |
esm-apps/bionic | released | 3.7.5-2ubuntu1~18.04.2+esm3 |
esm-infra-legacy/trusty | DNE | |
esm-infra/focal | DNE | |
focal | DNE | |
impish | DNE | |
jammy | DNE | |
kinetic | DNE | |
lunar | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support, was needed |
devel | DNE | |
esm-apps/bionic | released | 3.8.0-3ubuntu1~18.04.2+esm2 |
esm-infra-legacy/trusty | DNE | |
esm-infra/focal | not-affected | 3.8.10-0ubuntu1~20.04.4 |
focal | released | 3.8.10-0ubuntu1~20.04.4 |
impish | DNE | |
jammy | DNE | |
kinetic | DNE | |
lunar | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
devel | DNE | |
esm-apps/focal | needed | |
focal | ignored | end of standard support, was needed |
impish | not-affected | 3.9.7-2build1 |
jammy | DNE | |
kinetic | DNE | |
lunar | DNE | |
mantic | DNE | |
noble | DNE |
Показывать по
EPSS
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.
A flaw was found in Python, specifically within the urllib.parse modul ...
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.
EPSS
5 Medium
CVSS2
7.5 High
CVSS3