HIGH 7.5 Microsoft
CVE-2022-0391
A flaw was found in Python specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1 3.9.5 3.8.11 3.7.11 and 3.6.14.
Microsoft Security Update 2022-Feb: A flaw was found in Python specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1 3.9.5 3.8.11 3.7.11 and 3.6.14.
Affected Products
- cm1 python3 3.7.10-6 on CBL Mariner 1.0
- cm1 python2 2.7.18-9 on CBL Mariner 1.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-0391
- https://nvd.nist.gov/vuln/detail/CVE-2022-0391
This high severity vulnerability with a CVSS score of 7.5 was published on 2022-02-08 via Microsoft. EPSS score: 8.3% (top 5% of all CVEs by exploitation probability). Affected: cm1 python3 3.7.10-6 on CBL Mariner 1.0, cm1 python2 2.7.18-9 on CBL Mariner 1.0.
vulnfeed aggregates 10539 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.