7.1

CVE-2020-8492

Exploit
Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Python ≫ Python Version >= 2.7.0 <= 2.7.17
Python ≫ Python Version >= 3.5.0 <= 3.5.9
Python ≫ Python Version >= 3.6.0 <= 3.6.10
Python ≫ Python Version >= 3.7.0 <= 3.7.6
Python ≫ Python Version >= 3.8.0 <= 3.8.1
Opensuse ≫ Leap Version 15.1
Canonical ≫ Ubuntu Linux Version 12.04
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.10
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Fedoraproject ≫ Fedora Version 31
Fedoraproject ≫ Fedora Version 32
Debian ≫ Debian Linux Version 9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.62% 0.932
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
NIST 7.1 8.6 6.9
AV:N/AC:M/Au:N/C:N/I:N/A:C
CISA-ADP 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html
Third Party Advisory
Mailing List
https://usn.ubuntu.com/4333-1/
Third Party Advisory
https://usn.ubuntu.com/4333-2/
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html
Third Party Advisory
https://bugs.python.org/issue39503
Vendor Advisory
Issue Tracking
https://github.com/python/cpython/pull/18284
Patch
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
https://python-security.readthedocs.io/vuln/urllib-basic-auth-regex.html
Third Party Advisory
Exploit
https://security.gentoo.org/glsa/202005-09
Third Party Advisory
https://security.netapp.com/advisory/ntap-20200221-0001/
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A5NSAX4SC3V64PGZUPH7PRDLSON34Q5A/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UESGYI5XDAHJBATEZN3MHNDUBDH47AS6/
https://lists.apache.org/thread.html/rdb31a608dd6758c6093fd645aea3fbf022dd25b37109b6aaea5bc0b5%40%3Ccommits.cassandra.apache.org%3E
https://lists.apache.org/thread.html/rfec113c733162b39633fd86a2d0f34bf42ac35f711b3ec1835c774da%40%3Ccommits.cassandra.apache.org%3E
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WOKDEXLYW5UQ4S7PA7E37IITOC7C56J/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APGWEMYZIY5VHLCSZ3HD67PA5Z2UQFGH/