← לוח פגיעויות

CVE-2020-8492

בינונית 6.5

תיאור (מקור, אנגלית)

Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.

מדדים

CVSS 3.1
6.5 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS — סבירות ניצול
7% (אחוזון 100) נכון ל-8/10/2026
CWE
CWE-400

מוצרים מושפעים

python: python; opensuse: leap; canonical: ubuntu linux; fedoraproject: fedora; debian: debian linux

קישורים