VDB
ALINUX2-SA-2020%3A0178
ALINUX2-SA-2020%3A0178
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2020-11078: In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability impacts software that uses httplib2 with uri constructed by string concatenation, as opposed to proper urllib building with escaping. This has been fixed in 0.18.0.
Risk Scores
CVSS 3.1
6.800000190734863
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | fence-agents |
Timeline
- Nov 11, 2020 CVE Published
- Nov 11, 2020 CVE Updated