CRLF injection in httplib2 - CVE-2020-11078
Published: May 26, 2020
Vulnerability identifier: #VU28245
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11078
CWE-ID: CWE-93
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform CRLF injection attacks.
The vulnerability exists due to insufficient filtration of user-supplied data. A remote attacker controlling unescaped part of uri for "httplib2.Http.request()" can change request headers and body, send additional hidden requests to same server.
Affected software
httplib2
resource-agents (Red Hat package)
SUSE Linux Enterprise Module for Packagehub Subpackages
python-httplib2 (Red Hat package)
python3-httplib2
python2-httplib2
python-httplib2
fence-agents (Red Hat package)
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server
SUSE OpenStack Cloud
CentOS
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Resilient Storage for x86_64
Red Hat Enterprise Linux for Power, little endian
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise Module for Basesystem
openEuler
Red Hat OpenStack
resource-agents (Red Hat package)
SUSE Linux Enterprise Module for Packagehub Subpackages
python-httplib2 (Red Hat package)
python3-httplib2
python2-httplib2
python-httplib2
fence-agents (Red Hat package)
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server
SUSE OpenStack Cloud
CentOS
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Resilient Storage for x86_64
Red Hat Enterprise Linux for Power, little endian
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise Module for Basesystem
openEuler
Red Hat OpenStack
How to mitigate CVE-2020-11078
Install updates from vendor's website.
httplib2 - update to 0.18.0
resource-agents (Red Hat package) - addressed in versions 4.1.1-61.el7_9.4, 4.1.1-68.el8
python-httplib2 (Red Hat package) - update to 0.13.1-2.el8ost
python3-httplib2 - update to 0.13.1-5
python2-httplib2 - update to 0.13.1-5
python-httplib2 - update to 0.13.1-5
python-httplib2 - addressed in versions 0.18.1-1.el6, 0.18.1-3.el7, 0.18.1-3.fc31, 0.18.1-3.fc32
python3-httplib2 - addressed in versions 0.19.0-1.8.1, 0.19.0-3.3.1
python2-httplib2 - update to 0.19.0-3.3.1
python-httplib2 - addressed in versions 0.19.0-7.3.1, 0.19.0-7.7.1, 0.19.0-8.3.4
fence-agents (Red Hat package) - update to 4.2.1-41.el7_9.2
Red Hat OpenStack - update to 16.1.6
resource-agents (Red Hat package) - addressed in versions 4.1.1-61.el7_9.4, 4.1.1-68.el8
python-httplib2 (Red Hat package) - update to 0.13.1-2.el8ost
python3-httplib2 - update to 0.13.1-5
python2-httplib2 - update to 0.13.1-5
python-httplib2 - update to 0.13.1-5
python-httplib2 - addressed in versions 0.18.1-1.el6, 0.18.1-3.el7, 0.18.1-3.fc31, 0.18.1-3.fc32
python3-httplib2 - addressed in versions 0.19.0-1.8.1, 0.19.0-3.3.1
python2-httplib2 - update to 0.19.0-3.3.1
python-httplib2 - addressed in versions 0.19.0-7.3.1, 0.19.0-7.7.1, 0.19.0-8.3.4
fence-agents (Red Hat package) - update to 4.2.1-41.el7_9.2
Red Hat OpenStack - update to 16.1.6
External References
Related Security Bulletins
- CRLF injection in httplib2 library for Python
- Amazon Linux AMI update for python-httplib2
- Red Hat Enterprise Linux 8 update for resource-agents
- Red Hat Enterprise Linux 7 update for fence-agents
- Red Hat Enterprise Linux 7 update for resource-agents
- CentOS 7 update for resource-agents
- CentOS 7 update for fence-agents
- SUSE update for python-httplib2
- SUSE update for python-httplib2
- SUSE update for python-httplib2
- SUSE update for python-httplib2
- SUSE update for python-httplib2
- openEuler 20.03 LTS update for python-httplib2
- Multiple vulnerabilities in Red Hat OpenStack 16.1 packages
- Fedora 32 update for python-httplib2
- Fedora 31 update for python-httplib2
- Fedora EPEL 7 update for python-httplib2
- Fedora EPEL 6 update for python-httplib2