CVE-2019-9740
בינונית 6.1
תיאור (מקור, אנגלית)
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the query string after a ? character) followed by an HTTP header or a Redis command. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.
מדדים
- CVSS 3.1
-
6.1 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 5% (אחוזון 100) נכון ל-8/10/2026
- CWE
- CWE-93
מוצרים מושפעים
python: python
קישורים
- https://bugs.python.org/issue36276 ExploitIssue TrackingVendor Advisory
- https://bugs.python.org/issue36276 ExploitIssue TrackingVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00039.html Mailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00041.html Mailing ListThird Party Advisory
- http://packetstormsecurity.com/files/154927/Slackware-Security-Advisory-python… Third Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2021/02/04/2 Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/107466 Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:1260 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2030 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3335 Third Party Advisory