VDB

GCVE-VVD-MAGEIA-2021-55

GCVE-VVD-MAGEIA-2021-55
Advisory Published
Vulnetix · Advisory published March 30, 2021
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest() (CVE-2020-26137).

Affected Products

VendorProductVersionsPlatforms
Mageiabatik0 (affected), 1.14-1.3.mga8 (unaffected)
Mageiapython-urllib30 (affected), 1.24.3-1.2.mga7 (unaffected), 0 (affected), 1.24.3-1.2.mga7 (unaffected)

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›