VDB

ALINUX2-SA-2020%3A0178

ALINUX2-SA-2020%3A0178 PUBLISHED CVSS 6.800000190734863 MEDIUM

Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2020-11078: In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability impacts software that uses httplib2 with uri constructed by string concatenation, as opposed to proper urllib building with escaping. This has been fixed in 0.18.0.

Risk Scores

CVSS 3.1
6.800000190734863
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N

Affected Products

VendorProductVersions
Alibaba Cloudfence-agents

Timeline

  • Nov 11, 2020 CVE Published
  • Nov 11, 2020 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›