CVE-2020-11078
Summary
| CVE | CVE-2020-11078 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-05-20 16:15:00 UTC |
| Updated | 2023-11-07 03:14:00 UTC |
| Description | In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability impacts software that uses httplib2 with uri constructed by string concatenation, as opposed to proper urllib building with escaping. This has been fixed in 0.18.0. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 31 Update: python-httplib2-0.18.1-3.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| Pony Mail! |
|
lists.apache.org |
|
| [SECURITY] Fedora 32 Update: python-httplib2-0.18.1-3.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| [SECURITY] [DLA 2232-1] python-httplib2 security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Third Party Advisory |
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Third Party Advisory |
| [SECURITY] Fedora 31 Update: python-httplib2-0.18.1-3.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Third Party Advisory |
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Third Party Advisory |
| Pony Mail! |
|
lists.apache.org |
|
| CWE-93 CRLF injection in httplib2 · Advisory · httplib2/httplib2 · GitHub |
CONFIRM |
github.com |
Patch, Third Party Advisory |
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Third Party Advisory |
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Patch, Third Party Advisory |
| IMPORTANT security vulnerability CWE-93 CRLF injection · httplib2/httplib2@a1457cc · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| Pony Mail! |
|
lists.apache.org |
|
| [SECURITY] Fedora 32 Update: python-httplib2-0.18.1-3.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
|
lists.apache.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159680 Oracle Enterprise Linux Security Update for resource-agents security and bug fix update (ELSA-2020-5004)
- 356229 Amazon Linux Security Advisory for python-httplib2 : ALASANSIBLE2-2023-007
- 356481 Amazon Linux Security Advisory for python-httplib2 : ALAS2ANSIBLE2-2023-007
- 377530 Alibaba Cloud Linux Security Update for fence-agents (ALINUX2-SA-2020:0178)
- 378148 Virtuozzo Linux Security Update for fence-agents-mpath (VZLSA-2020:5003)
- 378215 Virtuozzo Linux Security Update for resource-agents-aliyun (VZLSA-2020:5004)
- 750016 SUSE Enterprise Linux Security Update for python-httplib2 (SUSE-SU-2021:1637-1)
- 750086 SUSE Enterprise Linux Security Update for python-httplib2 (SUSE-SU-2021:1806-1)
- 750087 SUSE Enterprise Linux Security Update for python-httplib2 (SUSE-SU-2021:1807-1)
- 750195 OpenSUSE Security Update for python-httplib2 (openSUSE-SU-2021:0772-1)
- 750764 OpenSUSE Security Update for python-httplib2 (openSUSE-SU-2021:1806-1)
- 983131 Python (pip) Security Update for httplib2 (GHSA-gg84-qgv9-w4pq)