CRLF injection in urllib3 - CVE-2020-26137

 

CRLF injection in urllib3 - CVE-2020-26137

Published: September 30, 2020 / Updated: July 20, 2022


Vulnerability identifier: #VU47403
CSH Severity: Medium
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-26137
CWE-ID: CWE-93
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject arbitrary data in server response.

The vulnerability exists due to insufficient validation of attacker-supplied data passed via the "method" parameter. A remote authenticated attacker can pass specially crafted data to the application containing CR-LF characters and modify application behavior.


Affected software

urllib3
Cloud Pak for Security (CP4S)
RecoverPoint for Virtual Machines
IBM Qradar SIEM
IBM Process Mining
Red Hat Advanced Cluster Management for Kubernetes
Splunk User Behavior Analytics (UBA)
IBM Cloud Pak for Business Automation
IBM Cloud Pak for Data System
IBM Cloud Pak for Data Scheduling
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Spectrum Symphony
Dell NetWorker Virtual Edition
python-urllib3 (Red Hat package)
py3-urllib3 (Alpine package)
SUSE Linux Enterprise Module for Packagehub Subpackages
python3-pyasn1
python2-pyasn1
python3-trustme
python3-asn1crypto
python2-asn1crypto
python-urllib3 (Ubuntu package)
python3-urllib3 (Ubuntu package)
python3-cffi
python3-cffi-debuginfo
python2-cffi-debuginfo
python2-cffi
python-cffi-debugsource
python-cffi-debuginfo
python2-boto3
python3-boto3
aws-cli
python3-botocore
python2-botocore
python3-urllib3
python-urllib3
python2-urllib3
python2-cryptography
python3-cryptography
python3-cryptography-debuginfo
python-cryptography-debuginfo
python2-cryptography-debuginfo
python-cryptography-debugsource
python3-pycparser
python2-pycparser
golang-github-prometheus-alertmanager (Red Hat package)
openshift-ansible (Red Hat package)
atomic-openshift-cluster-autoscaler (Red Hat package)
atomic-openshift (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
atomic-openshift-metrics-server (Red Hat package)
openshift-enterprise-autoheal (Red Hat package)
atomic-openshift-node-problem-detector (Red Hat package)
atomic-openshift-descheduler (Red Hat package)
openshift-enterprise-cluster-capacity (Red Hat package)
golang-github-openshift-oauth-proxy (Red Hat package)
atomic-openshift-dockerregistry (Red Hat package)
atomic-openshift-web-console (Red Hat package)
golang-github-prometheus-node_exporter (Red Hat package)
openshift-kuryr (Red Hat package)
atomic-enterprise-service-catalog (Red Hat package)
golang-github-prometheus-prometheus (Red Hat package)
python2-pyOpenSSL
python3-pyOpenSSL
python3-service_identity
Dell EMC PowerProtect Data Protection
Cloud Pak for Network Automation
SmartFabric OS10
xDoctor4ECS
SOAR QRadar Plugin App
XtremIO X2
IBM QRadar Incident Forensics
Maximo Application Suite - IoT Component
NetWorker Management Console (NMC)
Robotic Process Automation for Cloud Pak
Red Hat OpenShift Container Platform
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE MicroOS
SUSE Enterprise Storage
Oracle Linux
CentOS
Red Hat Enterprise Linux for Scientific Computing
Fedora
Red Hat Enterprise Linux for x86_64
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Python2
Ubuntu
IBM Security Guardium
OpenShift Virtualization

How to mitigate CVE-2020-26137

Install updates from vendor's website.

urllib3 - update to 1.25.9
Cloud Pak for Security (CP4S) - update to 1.8.0.0
IBM Process Mining - update to 2.0
python-urllib3 (Red Hat package) - addressed in versions 1.24.2-5.el8, 1.26.2-1.el7
py3-urllib3 (Alpine package) - update to 1.26.2-r1
Red Hat Advanced Cluster Management for Kubernetes - update to 2.3.12
Dell EMC PowerProtect Data Protection - update to 2.7.8
Cloud Pak for Network Automation - update to 2.7.4
Red Hat OpenShift Container Platform - addressed in versions 3.11.374, 3.11.784
Splunk User Behavior Analytics (UBA) - update to 5.4.2
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
IBM Qradar SIEM - update to 7.5.0 Update Pack 10
SmartFabric OS10 - addressed in versions 10.5.4.11, 10.5.6.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.26, 23.0.1.4
python3-pyasn1 - update to 0.4.2-3.2.1
python2-pyasn1 - update to 0.4.2-3.2.1
python3-trustme - update to 0.6.0-3.3.1
python3-asn1crypto - update to 0.24.0-3.2.1
python2-asn1crypto - update to 0.24.0-3.2.1
python-urllib3 (Ubuntu package) - addressed in versions 1.13.1-2ubuntu0.16.04.4, 1.22-1ubuntu0.18.04.2
python3-urllib3 (Ubuntu package) - addressed in versions 1.13.1-2ubuntu0.16.04.4, 1.22-1ubuntu0.18.04.2, 1.25.8-2ubuntu0.1
python3-cffi - update to 1.13.2-3.2.5
python3-cffi-debuginfo - update to 1.13.2-3.2.5
python2-cffi-debuginfo - update to 1.13.2-3.2.5
python2-cffi - update to 1.13.2-3.2.5
python-cffi-debugsource - update to 1.13.2-3.2.5
python-cffi-debuginfo - update to 1.13.2-3.2.5
python2-boto3 - update to 1.17.9-19.1
python3-boto3 - update to 1.17.9-19.1
aws-cli - update to 1.19.9-26.1
python3-botocore - update to 1.20.9-33.1
python2-botocore - update to 1.20.9-33.1
python3-urllib3 - update to 1.25.6-2.el7
python3-urllib3 - addressed in versions 1.25.10-3.31.2, 1.25.10-9.14.1
python-urllib3 - update to 1.25.10-3.31.2
python2-urllib3 - update to 1.25.10-9.14.1
IBM Cloud Pak for Data System - update to 2.0.2.1.IF1
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
python2-cryptography - update to 2.8-10.1
python3-cryptography - update to 2.8-10.1
python3-cryptography-debuginfo - update to 2.8-10.1
python-cryptography-debuginfo - update to 2.8-10.1
python2-cryptography-debuginfo - update to 2.8-10.1
python-cryptography-debugsource - update to 2.8-10.1
python3-pycparser - update to 2.17-3.2.1
python2-pycparser - update to 2.17-3.2.1
golang-github-prometheus-alertmanager (Red Hat package) - update to 3.11.374-1.git.0.3abd2a5.el7
openshift-ansible (Red Hat package) - update to 3.11.374-1.git.0.92f5956.el7
atomic-openshift-cluster-autoscaler (Red Hat package) - update to 3.11.374-1.git.0.2996f62.el7
atomic-openshift (Red Hat package) - update to 3.11.374-1.git.0.ebd3ee9.el7
atomic-openshift-service-idler (Red Hat package) - update to 3.11.374-1.git.15.523a1f7.el7
atomic-openshift-metrics-server (Red Hat package) - update to 3.11.374-1.git.53.9df25a9.el7
openshift-enterprise-autoheal (Red Hat package) - update to 3.11.374-1.git.218.9cf7939.el7
atomic-openshift-node-problem-detector (Red Hat package) - update to 3.11.374-1.git.263.28335fb.el7
atomic-openshift-descheduler (Red Hat package) - update to 3.11.374-1.git.299.f128e96.el7
openshift-enterprise-cluster-capacity (Red Hat package) - update to 3.11.374-1.git.379.80bd08f.el7
golang-github-openshift-oauth-proxy (Red Hat package) - update to 3.11.374-1.git.439.966c536.el7
atomic-openshift-dockerregistry (Red Hat package) - update to 3.11.374-1.git.481.e6a880c.el7
atomic-openshift-web-console (Red Hat package) - update to 3.11.374-1.git.647.9e78d83.el7
golang-github-prometheus-node_exporter (Red Hat package) - update to 3.11.374-1.git.1062.490d6d5.el7
openshift-kuryr (Red Hat package) - update to 3.11.374-1.git.1478.ef11824.el7
atomic-enterprise-service-catalog (Red Hat package) - update to 3.11.374-1.git.1675.738abcc.el7
golang-github-prometheus-prometheus (Red Hat package) - update to 3.11.374-1.git.5026.29379c4.el7
IBM Cloud Pak for Data Scheduling - update to 4.8.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.3
xDoctor4ECS - update to 4.8-84.0
SOAR QRadar Plugin App - update to 5.4.0
XtremIO X2 - update to 6.4.1-11
IBM Spectrum Symphony - update to 7.3.2 Fix 601860
IBM QRadar Incident Forensics - update to 7.5.0.10
Maximo Application Suite - IoT Component - addressed in versions 8.7.21, 8.8.17, 9.0.7
python2-pyOpenSSL - update to 17.5.0-8.3.1
python3-pyOpenSSL - update to 17.5.0-8.3.1
python3-service_identity - update to 18.1.0-3.3.1
NetWorker Management Console (NMC) - update to 19.11
Dell NetWorker Virtual Edition - update to 19.11
Robotic Process Automation for Cloud Pak - update to 21.0.7.8

External References

Related Security Bulletins