CVE-2020-26116
Public on 2020-09-27
Modified on 2021-06-22
Description
A flaw was found in Python. The built-in modules httplib and http.client (included in Python 2 and Python 3, respectively) do not properly validate CRLF sequences in the HTTP request method, potentially allowing manipulation to the request by injecting additional HTTP headers. The highest threat from this vulnerability is to confidentiality and integrity.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 2 - Core | python | 2021-06-16 | ALAS2-2021-1669 | Fixed |
Amazon Linux 1 | python27 | 2020-11-16 | ALAS-2020-1454 | Fixed |
Amazon Linux 2 - Core | python3 | 2021-06-16 | ALAS2-2021-1670 | Fixed |
Amazon Linux 2 - Core | python3 | 2023-10-25 | ALAS2-2023-2317 | Fixed |
Amazon Linux 1 | python34 | 2020-11-16 | ALAS-2020-1454 | Fixed |
Amazon Linux 1 | python35 | 2020-11-16 | ALAS-2020-1454 | Fixed |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 6.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
NVD | CVSSv2 | 6.4 | AV:N/AC:L/Au:N/C:P/I:P/A:N |
NVD | CVSSv3 | 7.2 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |