CVE-2020-8492
Vulnerability Summary
Timeline
Description
Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.
CVSS Metrics
- v3.1•MEDIUM•Score: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- v2.0•HIGH•Score: 7.1AV:N/AC:M/Au:N/C:N/I:N/A:C
EPSS Trends
Current EPSS score: 6.62%• Percentile: 94%
Techniques & Countermeasures
- CWE-400•Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
Affected Systems
- alpine•python3
< 3.7.7-r0 | < 3.8.2-r0 | < 3.8.2-r0 | < 3.8.2-r0 | < 3.8.2-r0 | < 3.8.2-r0 | < 3.8.2-r0 | < 3.8.2-r0 | < 3.8.2-r0 | < 3.8.2-r0 | < 3.8.2-r0 | < 3.8.2-r0 | < 3.8.2-r0 | < 3.8.2-r0 | < 3.8.2-r0
- canonical•ubuntu_linux
12.04 | 14.04 | 16.04 | 18.04 | 19.10 | 20.04
- debian•python2.7
< 2.7.18-2
- debian•debian_linux
9.0
- fedoraproject•fedora
31 | 32
- opensuse•leap
15.1
- python•python
≥ 2.7.0, ≤ 2.7.17 | ≥ 3.5.0, ≤ 3.5.9 | ≥ 3.6.0, ≤ 3.6.10 | ≥ 3.7.0, ≤ 3.7.6 | ≥ 3.8.0, ≤ 3.8.1
References (18)
- https://bugs.python.org/issue39503
- https://python-security.readthedocs.io/vuln/urllib-basic-auth-regex.html
- https://github.com/python/cpython/pull/18284
- https://security.netapp.com/advisory/ntap-20200221-0001/
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html
- https://usn.ubuntu.com/4333-1/
- https://usn.ubuntu.com/4333-2/
- https://security.gentoo.org/glsa/202005-09
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APGWEMYZIY5VHLCSZ3HD67PA5Z2UQFGH/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WOKDEXLYW5UQ4S7PA7E37IITOC7C56J/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UESGYI5XDAHJBATEZN3MHNDUBDH47AS6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A5NSAX4SC3V64PGZUPH7PRDLSON34Q5A/
- https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html
- https://lists.apache.org/thread.html/rdb31a608dd6758c6093fd645aea3fbf022dd25b37109b6aaea5bc0b5%40%3Ccommits.cassandra.apache.org%3E
- https://lists.apache.org/thread.html/rfec113c733162b39633fd86a2d0f34bf42ac35f711b3ec1835c774da%40%3Ccommits.cassandra.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
- https://security.alpinelinux.org/vuln/CVE-2020-8492
- https://security-tracker.debian.org/tracker/CVE-2020-8492