A flaw was found in Python. The built-in modules httplib and http.client (included in Python 2 and Python 3, respectively) do not properly validate CRLF sequences in the HTTP request method, potentially allowing manipulation to the request by injecting additional HTTP headers. The highest threat from this vulnerability is to confidentiality and integrity.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 2 - Core | python | 2021-06-16 20:37 | ALAS2-2021-1669 |
Amazon Linux 1 | python27 | 2020-11-16 17:59 | ALAS-2020-1454 |
Amazon Linux 2 - Core | python3 | 2023-10-25 21:40 | ALAS2-2023-2317 |
Amazon Linux 2 - Core | python3 | 2021-06-16 20:37 | ALAS2-2021-1670 |
Amazon Linux 1 | python34 | 2020-11-16 17:59 | ALAS-2020-1454 |
Amazon Linux 1 | python35 | 2020-11-16 17:59 | ALAS-2020-1454 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 6.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
NVD | CVSSv2 | 6.4 | AV:N/AC:L/Au:N/C:P/I:P/A:N |
NVD | CVSSv3 | 7.2 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |