CVE-2020-35678

Autobahn|Python before 20.12.3 allows redirect header injection.
Open Redirect
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 71.1%
Affected Products (NVD)
VendorProductVersion
crossbarautobahn
𝑥
< 20.12.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
python-autobahn
bookworm
22.7.1+dfsg1-2
fixed
bullseye
17.10.1+dfsg1-7
fixed
buster
no-dsa
sid
22.7.1+dfsg1-4
fixed
stretch
ignored
trixie
22.7.1+dfsg1-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-autobahn
bionic
needed
focal
needed
groovy
ignored
hirsute
ignored
impish
ignored
jammy
needed
kinetic
ignored
lunar
ignored
mantic
ignored
noble
needed
oracular
ignored
plucky
ignored
questing
ignored
resolute
needed
trusty
dne
xenial
needed