571
VMScore

CVE-2020-26137

Published: 30/09/2020 Updated: 08/10/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 6.5 | Impact Score: 2.5 | Exploitability Score: 3.9
VMScore: 571
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

urllib3 prior to 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

python urllib3

canonical ubuntu linux 18.04

canonical ubuntu linux 20.04

canonical ubuntu linux 16.04

debian debian linux 9.0

oracle zfs storage appliance kit 8.8

oracle communications cloud native core network function cloud native environment 22.2.0

Vendor Advisories

Synopsis Important: OpenShift Container Platform 4527 packages and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 4527 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release also includes ...
Synopsis Moderate: rh-python38 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for rh-python38-python, rh-python38-python-psutil, and rh-python38-python-urllib3 is now available for Red Hat Software CollectionsRed Hat Product Security has rated this updat ...
概述 Moderate: python security update 类型/严重性 Security Advisory: Moderate 标题 An update for python is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating ...
Synopsis Moderate: Red Hat Advanced Cluster Management 2312 security updates and bug fixes Type/Severity Security Advisory: Moderate Topic Red Hat Advanced Cluster Management for Kubernetes 2312 GeneralAvailability release images, which provide security updates and bug fixesRed Hat Product Security has rated this update as having a secur ...
Synopsis Moderate: OpenShift Container Platform 311374 bug fix and security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 311374 is now available with updates to packages and images that fix several bugsThis release also includes a security update f ...
Synopsis Moderate: OpenShift Container Platform 311784 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 311784 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Container Pl ...
A flaw was found in python-urllib3 The HTTPConnectionrequest() does not properly validate CRLF sequences in the HTTP request method, potentially allowing manipulation of the request by injecting additional HTTP headers The highest threat from this vulnerability is to confidentiality and integrity (CVE-2020-26137) ...

Github Repositories

Security audit Python project dependencies against security advisory databases.

Skjold /skjɔl/ ,- | , ,- | ,-| `- |< | | | | | | Security audit python project dependencies `-' ' ` | `-' `' `-´ against several security advisory databases `' Introduction It currently supports fetching advisories from the following sou

Deep dive into Clair image vulnerability scanning

Deep Dive into Clair Image Vulnerability Scanning Clair Documentation What is ClairCore Updaters and Defaults Vulnerability Databases Alpine security database secdbalpinelinuxorg/ Amazon Linux security database repodata/updateinfoxmlgz cdnamazonlinuxcom/2/core/20/x86_64/3c5ff503186aefc295ca296adf15aa0884f998fff0c78d5fc6448735eb664d26/repodata/updateinf