ZeroHour

CVE-2019-9948

PoC
CVSS 3.1
9.1 critical
EPSS
12%p96
Published
()
Modified
Description

urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call.

Vendors
pythonopensusedebianfedoraprojectcanonicalredhat
Products
python, leap, debian linux, fedora, ubuntu linux, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server eus, enterprise linux tus, enterprise linux workstation
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.