CVE-2021-3733
10.03.2022, 17:42
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.Enginsight
| Vendor | Product | Version |
|---|---|---|
| python | python | 𝑥 < 3.6.14 |
| python | python | 3.7.0 ≤ 𝑥 < 3.7.11 |
| python | python | 3.8.0 ≤ 𝑥 < 3.8.10 |
| python | python | 3.9.0 ≤ 𝑥 < 3.9.5 |
| python | python | 3.10.0 |
| redhat | codeready_linux_builder | 8.0 |
| redhat | codeready_linux_builder_for_ibm_z_systems | 8.0 |
| redhat | codeready_linux_builder_for_power_little_endian | 8.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux_eus | 8.4 |
| redhat | enterprise_linux_for_ibm_z_systems | 8.0 |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 8.4 |
| redhat | enterprise_linux_for_power_little_endian | 8.0 |
| redhat | enterprise_linux_for_power_little_endian_eus | 8.4 |
| redhat | enterprise_linux_server_aus | 8.4 |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 8.4 |
| redhat | enterprise_linux_server_tus | 8.4 |
| redhat | enterprise_linux_server_update_services_for_sap_solutions | 8.4 |
| fedoraproject | extra_packages_for_enterprise_linux | 7.0 |
| netapp | management_services_for_element_software_and_netapp_hci | - |
| netapp | ontap_select_deploy_administration_utility | - |
| netapp | solidfire\,_enterprise_sds_\&_hci_storage_node | - |
| netapp | hci_compute_node_firmware | - |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| python3.10 |
| ||||||||||||||||||||||
| python3.4 |
| ||||||||||||||||||||||
| python3.5 |
| ||||||||||||||||||||||
| python3.6 |
| ||||||||||||||||||||||
| python3.7 |
| ||||||||||||||||||||||
| python3.8 |
| ||||||||||||||||||||||
| python3.9 |
|
References