Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20378
HistoryMay 27, 2019 - 12:40 a.m.

CRLF Injection

2019-05-2700:40:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.004 Low

EPSS

Percentile

72.1%

Python is vulnerable to CRLF Injection. Remote unauthenticated attacker could exploit the flaw by controling a url parameter, as demonstrated in the first argument to urllib.request.urlopen with \r\n (specifically in the query string after a ? character) followed by an HTTP header or a Redis command.

References