Lack of data validation In urllib3
Description
Improper Neutralization of CRLF Sequences in urllib3 library for Python In the urllib3 library through 1.24.2 for Python, CRLF injection is possible if the attacker controls the request parameter.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
pypi | 1.24.3 | ||
debian 13 | 1.25.6-4 | ||
debian 14 | 1.25.6-4 | ||
debian 11 | 1.25.6-4 | ||
debian 12 | 1.25.6-4 | ||
rpm rhel8 | 0:1.24.2-2.el8 | ||
rpm rhel7 | 0:9.0.3-7.el7_8 | ||
rpm rhel8 | 0:9.0.3-16.el8 | ||
rpm rhel7 | 0:15.1.0-4.el7_8 | ||
rpm rhel6 | - | - |
1-10 of 11
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10.