CVE-2019-9947
בינונית 6.1
תיאור (מקור, אנגלית)
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the path component of a URL that lacks a ? character) followed by an HTTP header or a Redis command. This is similar to the CVE-2019-9740 query string issue. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.
מדדים
- CVSS 3.1
-
6.1 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 5% (אחוזון 100) נכון ל-8/10/2026
- CWE
- CWE-93
מוצרים מושפעים
python: python
קישורים
- https://bugs.python.org/issue35906 ExploitIssue TrackingPatchVendor Advisory
- https://bugs.python.org/issue35906 ExploitIssue TrackingPatchVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00062.html Mailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00063.html Mailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/02/04/2 Mailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1260 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2030 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3335 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3520 Third Party Advisory