MEDIUM 6.5 Microsoft
CVE-2020-26137
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
Microsoft Security Update 2020-Sep: urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
Affected Products
- cm1 python-urllib3 1.25.9-2 on CBL Mariner 1.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-26137
- https://nvd.nist.gov/vuln/detail/CVE-2020-26137
This medium severity vulnerability with a CVSS score of 6.5 was published on 2020-09-08 via Microsoft. Affected: cm1 python-urllib3 1.25.9-2 on CBL Mariner 1.0.
vulnfeed aggregates 9909 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.