CVE-2020-8492
⚪ Do wiadomości
Atak ReDoS w Pythonie umożliwia serwerowi HTTP przeciążenie klienta.
CVSS
6.5
EPSS
6.6%
Exploit
poc
Vendor
canonical
Opis źródłowy (NVD)
Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.
dos exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 6.6% |
| Opublikowano (NVD) | 2020-01-30 19:15:12 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 19:17:18 UTC |
Referencje
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html ([email protected]) [Third Party Advisory]
- https://bugs.python.org/issue39503 ([email protected]) [Issue Tracking, Vendor Advisory]
- https://github.com/python/cpython/pull/18284 ([email protected]) [Patch, Third Party Advisory]
- https://lists.apache.org/thread.html/rdb31a608dd6758c6093fd645aea3fbf022dd25b37109b6aaea5bc0b5%40%3Ccommits.cassandra.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/rfec113c733162b39633fd86a2d0f34bf42ac35f711b3ec1835c774da%40%3Ccommits.cassandra.apache.org%3E ([email protected])
- https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html ([email protected]) [Mailing List, Third Party Advisory]
- https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html ([email protected])
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WOKDEXLYW5UQ4S7PA7E37IITOC7C56J/ ([email protected])
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A5NSAX4SC3V64PGZUPH7PRDLSON34Q5A/ ([email protected])
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APGWEMYZIY5VHLCSZ3HD67PA5Z2UQFGH/ ([email protected])
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UESGYI5XDAHJBATEZN3MHNDUBDH47AS6/ ([email protected])
- https://python-security.readthedocs.io/vuln/urllib-basic-auth-regex.html ([email protected]) [Exploit, Third Party Advisory]
- https://security.gentoo.org/glsa/202005-09 ([email protected]) [Third Party Advisory]
- https://security.netapp.com/advisory/ntap-20200221-0001/ ([email protected]) [Third Party Advisory]
- https://usn.ubuntu.com/4333-1/ ([email protected]) [Third Party Advisory]
- https://usn.ubuntu.com/4333-2/ ([email protected]) [Third Party Advisory]