CVE-2020-26137
30.09.2020, 18:15
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
Vendor | Product | Version |
---|---|---|
python | urllib3 | 𝑥 < 1.25.9 |
canonical | ubuntu_linux | 16.04 |
canonical | ubuntu_linux | 18.04 |
canonical | ubuntu_linux | 20.04 |
debian | debian_linux | 9.0 |
oracle | communications_cloud_native_core_network_function_cloud_native_environment | 22.2.0 |
oracle | zfs_storage_appliance_kit | 8.8 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
python-pip |
| ||||||||||||||||||||||||
python-urllib3 |
|
References