Back

MEDIUM

python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service

Published Apr 15, 2019

Description

In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.

Affected products

Remediation

Red Hat statement

This issue affects the version of python-urllib3 shipped with Red Hat Gluster Storage 3, as it is vulnerable to CRLF injection. Red Hat Satellite 6.2 is on Maintenance Support 2 phase, hence only selected critical and important issues will be fixed. Please refer to Red Hat Satellite Product Life Cycle page for more information. In Red Hat OpenStack Platform 13, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP python-urllib3 package.

Metrics

Weaknesses (2)

References (25)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 15, 2019
Updated Aug 4, 2024
Reserved Apr 15, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 13, 2019
GHSA-R64Q-W8JR-G9QP