Extended Lifecycle Support CVE dashboard by TuxСare

CVEs Releases Projects

CVE-2022-0391

Updated: 2022-06-16 20:17:57.737701

Description:

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 5
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Status Errata Last updated
CentOS 6 ELS python 2.6.6 Released CLSA-2022:1646665957 2022-05-05 12:04:46.59549
CentOS 8.4 ELS python3 3.6.8 Released CLSA-2022:1653920195 2022-05-30 11:37:29.458479
CentOS 8.4 ELS python2 2.7.18 Released CLSA-2022:1654525948 2022-06-06 11:47:17.545515
CentOS 8.5 ELS python3 3.6.8 Released CLSA-2022:1654010877 2022-05-31 11:38:04.238365
CentOS 8.5 ELS python2 2.7.18 Released CLSA-2022:1654526367 2022-06-06 11:47:17.108732
CloudLinux 6 ELS python 2.6.6 Released CLSA-2022:1646666376 2022-04-19 21:49:56.826362
Oracle Linux 6 ELS python 2.6.6 Released CLSA-2022:1646666442 2022-04-19 21:49:56.876529
Ubuntu 16.04 ELS python 2.7.12-1ubuntu0~16.04.13 Released CLSA-2022:1647254655 2022-04-19 21:49:56.897155
Ubuntu 16.04 ELS python3 3.5.2-2ubuntu0~16.04.13 Released CLSA-2022:1654106859 2022-06-01 14:35:37.521581