Lucene search

K
redhatcveRedhat.comRH:CVE-2020-8492
HistoryMar 02, 2020 - 11:41 a.m.

CVE-2020-8492

2020-03-0211:41:02
redhat.com
access.redhat.com
21

0.006 Low

EPSS

Percentile

78.5%

Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.