ZeroHour

CVE-2020-8492

PoC
CVSS 3.1
6.5 medium
EPSS
7%p93
Published
()
Modified
Description

Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.

Vendors
pythonopensusecanonicalfedoraprojectdebian
Products
python, leap, ubuntu linux, fedora, debian linux
Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.