CRLF injection in httplib2 - CVE-2020-11078

 

CRLF injection in httplib2 - CVE-2020-11078

Published: May 26, 2020


Vulnerability identifier: #VU28245
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11078
CWE-ID: CWE-93
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform CRLF injection attacks.

The vulnerability exists due to insufficient filtration of user-supplied data. A remote attacker controlling unescaped part of uri for "httplib2.Http.request()" can change request headers and body, send additional hidden requests to same server.


Affected software

httplib2
resource-agents (Red Hat package)
SUSE Linux Enterprise Module for Packagehub Subpackages
python-httplib2 (Red Hat package)
python3-httplib2
python2-httplib2
python-httplib2
fence-agents (Red Hat package)
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server
SUSE OpenStack Cloud
CentOS
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Resilient Storage for x86_64
Red Hat Enterprise Linux for Power, little endian
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise Module for Basesystem
openEuler
Red Hat OpenStack

How to mitigate CVE-2020-11078

Install updates from vendor's website.

httplib2 - update to 0.18.0
resource-agents (Red Hat package) - addressed in versions 4.1.1-61.el7_9.4, 4.1.1-68.el8
python-httplib2 (Red Hat package) - update to 0.13.1-2.el8ost
python3-httplib2 - update to 0.13.1-5
python2-httplib2 - update to 0.13.1-5
python-httplib2 - update to 0.13.1-5
python-httplib2 - addressed in versions 0.18.1-1.el6, 0.18.1-3.el7, 0.18.1-3.fc31, 0.18.1-3.fc32
python3-httplib2 - addressed in versions 0.19.0-1.8.1, 0.19.0-3.3.1
python2-httplib2 - update to 0.19.0-3.3.1
python-httplib2 - addressed in versions 0.19.0-7.3.1, 0.19.0-7.7.1, 0.19.0-8.3.4
fence-agents (Red Hat package) - update to 4.2.1-41.el7_9.2
Red Hat OpenStack - update to 16.1.6

External References

Related Security Bulletins