CVE-2020-8492
PoC —CVSS 3.1
6.5 medium
EPSS
7%p93
Published
()
Modified
Description
Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.
- Vendors
- pythonopensusecanonicalfedoraprojectdebian
- Products
- python, leap, ubuntu linux, fedora, debian linux
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.