Lucene search

K
hackeronePush0ebpH1:590020
HistoryMay 25, 2019 - 10:16 a.m.

Internet Bug Bounty: CRLF Injection in urllib

2019-05-2510:16:29
push0ebp
hackerone.com
92

EPSS

0.004

Percentile

72.8%

Hi. I found CRLF Injection a few months ago.
Please refer my bug issue.
https://bugs.python.org/issue35906

Thank you

Impact

lead to SSRF.
e.g. can exploit a internal redis server to send arbitrary packet data including ascii and non-ascii.