Lack of data validation In pypy3
Description
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 7.3.3+dfsg-1 | ||
debian 12 | 7.3.3+dfsg-1 | ||
debian 13 | 7.3.3+dfsg-1 | ||
debian 14 | 7.3.3+dfsg-1 | ||
debian 11 | - | ||
debian 11 | 3.9.0~b5-1 | ||
rpm rhel7 | 0:2.7.5-92.el7_9 | ||
rpm rhel8 | 0:3.6.8-37.el8 | ||
rpm rhel5 | - | - | |
rpm rhel6 | - | - |
1-10 of 13
10
Aliases
1. 2. 3. 4. 5.