CVE-2020-26137
30.09.2020, 18:15
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
| Vendor | Product | Version |
|---|---|---|
| python | urllib3 | 𝑥 < 1.25.9 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 20.04 |
| debian | debian_linux | 9.0 |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | 22.2.0 |
| oracle | zfs_storage_appliance_kit | 8.8 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| python-pip |
| ||||||||||||||||||||||||
| python-urllib3 |
|
References