Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20379
HistoryMay 27, 2019 - 12:40 a.m.

CRLF Injection

2019-05-2700:40:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
31

0.003 Low

EPSS

Percentile

65.2%

Python is vulnerable to CRLF Injection. Remote unauthenticated attacker could exploit the flaw by controling a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the path component of a URL that lacks a ? character) followed by an HTTP header or a Redis command.

References