urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
| Software | From | Fixed in |
|---|---|---|
| python / urllib3 | - | 1.25.9 |
| canonical / ubuntu_linux | 18.04 | 18.04.x |
| canonical / ubuntu_linux | 20.04 | 20.04.x |
| canonical / ubuntu_linux | 16.04 | 16.04.x |
| debian / debian_linux | 9.0 | 9.0.x |
| oracle / zfs_storage_appliance_kit | 8.8 | 8.8.x |
| oracle / communications_cloud_native_core_network_function_cloud_native_environment | 22.2.0 | 22.2.0.x |
urllib3
|
- | 1.25.9 |