CVE-2020-8492
בינונית 6.5
תיאור (מקור, אנגלית)
Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.
מדדים
- CVSS 3.1
-
6.5 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 7% (אחוזון 100) נכון ל-8/10/2026
- CWE
- CWE-400
מוצרים מושפעים
python: python; opensuse: leap; canonical: ubuntu linux; fedoraproject: fedora; debian: debian linux
קישורים
- https://bugs.python.org/issue39503 Issue TrackingVendor Advisory
- https://bugs.python.org/issue39503 Issue TrackingVendor Advisory
- https://github.com/python/cpython/pull/18284 PatchThird Party Advisory
- https://github.com/python/cpython/pull/18284 PatchThird Party Advisory
- https://python-security.readthedocs.io/vuln/urllib-basic-auth-regex.html ExploitThird Party Advisory
- https://python-security.readthedocs.io/vuln/urllib-basic-auth-regex.html ExploitThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html Third Party Advisory
- https://lists.apache.org/thread.html/rdb31a608dd6758c6093fd645aea3fbf022dd25b3…
- https://lists.apache.org/thread.html/rfec113c733162b39633fd86a2d0f34bf42ac35f7…
- https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html Mailing ListThird Party Advisory