HIGH 7.2 Microsoft
CVE-2020-26116
http.client in Python 3.x before 3.5.10 3.6.x before 3.6.12 3.7.x before 3.7.9 and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
Microsoft Security Update 2020-Sep: http.client in Python 3.x before 3.5.10 3.6.x before 3.6.12 3.7.x before 3.7.9 and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
Affected Products
- cm1 python3 3.7.10-3 on CBL Mariner 1.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-26116
- https://nvd.nist.gov/vuln/detail/CVE-2020-26116
This high severity vulnerability with a CVSS score of 7.2 was published on 2020-09-08 via Microsoft. EPSS score: 6.4% (top 7% of all CVEs by exploitation probability). Affected: cm1 python3 3.7.10-3 on CBL Mariner 1.0.
vulnfeed aggregates 9909 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.