Resource exhaustion in urllib3 - CVE-2020-7212

 

Resource exhaustion in urllib3 - CVE-2020-7212

Published: March 17, 2020


Vulnerability identifier: #VU26108
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-7212
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an inefficient algorithm in the "_encode_invalid_chars" function in "util/url.py". A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

urllib3
IBM Process Mining
IBM Cloud Pak for Data System
Cloud Pak for Network Automation
IBM QRadar Incident Forensics
IBM Qradar SIEM

How to mitigate CVE-2020-7212

Install updates from vendor's website.

urllib3 - update to 1.25.8
IBM Process Mining - update to 2.0
Cloud Pak for Network Automation - update to 2.7.4
IBM Qradar SIEM - update to 7.5.0 Update Pack 10
IBM Cloud Pak for Data System - update to 2.0.2.1.IF1
IBM QRadar Incident Forensics - update to 7.5.0.10

External References

Related Security Bulletins