ZeroHour

CVE-2020-26116

PoC
CVSS 3.1
7.2 high
EPSS
6%p93
Published
()
Modified
Description

http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.

Vendors
pythonfedoraprojectcanonicalnetappdebianoracleopensuse
Products
python, fedora, ubuntu linux, solidfire, hci storage node, debian linux, zfs storage appliance kit, leap
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.