CRLF injection in urllib3 - CVE-2020-26137
Published: September 30, 2020 / Updated: July 20, 2022
Vulnerability details
The vulnerability allows a remote attacker to inject arbitrary data in server response.
The vulnerability exists due to insufficient validation of attacker-supplied data passed via the "method" parameter. A remote authenticated attacker can pass specially crafted data to the application containing CR-LF characters and modify application behavior.
Affected software
Cloud Pak for Security (CP4S)
RecoverPoint for Virtual Machines
IBM Qradar SIEM
IBM Process Mining
Red Hat Advanced Cluster Management for Kubernetes
Splunk User Behavior Analytics (UBA)
IBM Cloud Pak for Business Automation
IBM Cloud Pak for Data System
IBM Cloud Pak for Data Scheduling
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Spectrum Symphony
Dell NetWorker Virtual Edition
python-urllib3 (Red Hat package)
py3-urllib3 (Alpine package)
SUSE Linux Enterprise Module for Packagehub Subpackages
python3-pyasn1
python2-pyasn1
python3-trustme
python3-asn1crypto
python2-asn1crypto
python-urllib3 (Ubuntu package)
python3-urllib3 (Ubuntu package)
python3-cffi
python3-cffi-debuginfo
python2-cffi-debuginfo
python2-cffi
python-cffi-debugsource
python-cffi-debuginfo
python2-boto3
python3-boto3
aws-cli
python3-botocore
python2-botocore
python3-urllib3
python-urllib3
python2-urllib3
python2-cryptography
python3-cryptography
python3-cryptography-debuginfo
python-cryptography-debuginfo
python2-cryptography-debuginfo
python-cryptography-debugsource
python3-pycparser
python2-pycparser
golang-github-prometheus-alertmanager (Red Hat package)
openshift-ansible (Red Hat package)
atomic-openshift-cluster-autoscaler (Red Hat package)
atomic-openshift (Red Hat package)
atomic-openshift-service-idler (Red Hat package)
atomic-openshift-metrics-server (Red Hat package)
openshift-enterprise-autoheal (Red Hat package)
atomic-openshift-node-problem-detector (Red Hat package)
atomic-openshift-descheduler (Red Hat package)
openshift-enterprise-cluster-capacity (Red Hat package)
golang-github-openshift-oauth-proxy (Red Hat package)
atomic-openshift-dockerregistry (Red Hat package)
atomic-openshift-web-console (Red Hat package)
golang-github-prometheus-node_exporter (Red Hat package)
openshift-kuryr (Red Hat package)
atomic-enterprise-service-catalog (Red Hat package)
golang-github-prometheus-prometheus (Red Hat package)
python2-pyOpenSSL
python3-pyOpenSSL
python3-service_identity
Dell EMC PowerProtect Data Protection
Cloud Pak for Network Automation
SmartFabric OS10
xDoctor4ECS
SOAR QRadar Plugin App
XtremIO X2
IBM QRadar Incident Forensics
Maximo Application Suite - IoT Component
NetWorker Management Console (NMC)
Robotic Process Automation for Cloud Pak
Red Hat OpenShift Container Platform
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE MicroOS
SUSE Enterprise Storage
Oracle Linux
CentOS
Red Hat Enterprise Linux for Scientific Computing
Fedora
Red Hat Enterprise Linux for x86_64
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Python2
Ubuntu
IBM Security Guardium
OpenShift Virtualization
How to mitigate CVE-2020-26137
Cloud Pak for Security (CP4S) - update to 1.8.0.0
IBM Process Mining - update to 2.0
python-urllib3 (Red Hat package) - addressed in versions 1.24.2-5.el8, 1.26.2-1.el7
py3-urllib3 (Alpine package) - update to 1.26.2-r1
Red Hat Advanced Cluster Management for Kubernetes - update to 2.3.12
Dell EMC PowerProtect Data Protection - update to 2.7.8
Cloud Pak for Network Automation - update to 2.7.4
Red Hat OpenShift Container Platform - addressed in versions 3.11.374, 3.11.784
Splunk User Behavior Analytics (UBA) - update to 5.4.2
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
IBM Qradar SIEM - update to 7.5.0 Update Pack 10
SmartFabric OS10 - addressed in versions 10.5.4.11, 10.5.6.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.26, 23.0.1.4
python3-pyasn1 - update to 0.4.2-3.2.1
python2-pyasn1 - update to 0.4.2-3.2.1
python3-trustme - update to 0.6.0-3.3.1
python3-asn1crypto - update to 0.24.0-3.2.1
python2-asn1crypto - update to 0.24.0-3.2.1
python-urllib3 (Ubuntu package) - addressed in versions 1.13.1-2ubuntu0.16.04.4, 1.22-1ubuntu0.18.04.2
python3-urllib3 (Ubuntu package) - addressed in versions 1.13.1-2ubuntu0.16.04.4, 1.22-1ubuntu0.18.04.2, 1.25.8-2ubuntu0.1
python3-cffi - update to 1.13.2-3.2.5
python3-cffi-debuginfo - update to 1.13.2-3.2.5
python2-cffi-debuginfo - update to 1.13.2-3.2.5
python2-cffi - update to 1.13.2-3.2.5
python-cffi-debugsource - update to 1.13.2-3.2.5
python-cffi-debuginfo - update to 1.13.2-3.2.5
python2-boto3 - update to 1.17.9-19.1
python3-boto3 - update to 1.17.9-19.1
aws-cli - update to 1.19.9-26.1
python3-botocore - update to 1.20.9-33.1
python2-botocore - update to 1.20.9-33.1
python3-urllib3 - update to 1.25.6-2.el7
python3-urllib3 - addressed in versions 1.25.10-3.31.2, 1.25.10-9.14.1
python-urllib3 - update to 1.25.10-3.31.2
python2-urllib3 - update to 1.25.10-9.14.1
IBM Cloud Pak for Data System - update to 2.0.2.1.IF1
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
python2-cryptography - update to 2.8-10.1
python3-cryptography - update to 2.8-10.1
python3-cryptography-debuginfo - update to 2.8-10.1
python-cryptography-debuginfo - update to 2.8-10.1
python2-cryptography-debuginfo - update to 2.8-10.1
python-cryptography-debugsource - update to 2.8-10.1
python3-pycparser - update to 2.17-3.2.1
python2-pycparser - update to 2.17-3.2.1
golang-github-prometheus-alertmanager (Red Hat package) - update to 3.11.374-1.git.0.3abd2a5.el7
openshift-ansible (Red Hat package) - update to 3.11.374-1.git.0.92f5956.el7
atomic-openshift-cluster-autoscaler (Red Hat package) - update to 3.11.374-1.git.0.2996f62.el7
atomic-openshift (Red Hat package) - update to 3.11.374-1.git.0.ebd3ee9.el7
atomic-openshift-service-idler (Red Hat package) - update to 3.11.374-1.git.15.523a1f7.el7
atomic-openshift-metrics-server (Red Hat package) - update to 3.11.374-1.git.53.9df25a9.el7
openshift-enterprise-autoheal (Red Hat package) - update to 3.11.374-1.git.218.9cf7939.el7
atomic-openshift-node-problem-detector (Red Hat package) - update to 3.11.374-1.git.263.28335fb.el7
atomic-openshift-descheduler (Red Hat package) - update to 3.11.374-1.git.299.f128e96.el7
openshift-enterprise-cluster-capacity (Red Hat package) - update to 3.11.374-1.git.379.80bd08f.el7
golang-github-openshift-oauth-proxy (Red Hat package) - update to 3.11.374-1.git.439.966c536.el7
atomic-openshift-dockerregistry (Red Hat package) - update to 3.11.374-1.git.481.e6a880c.el7
atomic-openshift-web-console (Red Hat package) - update to 3.11.374-1.git.647.9e78d83.el7
golang-github-prometheus-node_exporter (Red Hat package) - update to 3.11.374-1.git.1062.490d6d5.el7
openshift-kuryr (Red Hat package) - update to 3.11.374-1.git.1478.ef11824.el7
atomic-enterprise-service-catalog (Red Hat package) - update to 3.11.374-1.git.1675.738abcc.el7
golang-github-prometheus-prometheus (Red Hat package) - update to 3.11.374-1.git.5026.29379c4.el7
IBM Cloud Pak for Data Scheduling - update to 4.8.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.3
xDoctor4ECS - update to 4.8-84.0
SOAR QRadar Plugin App - update to 5.4.0
XtremIO X2 - update to 6.4.1-11
IBM Spectrum Symphony - update to 7.3.2 Fix 601860
IBM QRadar Incident Forensics - update to 7.5.0.10
Maximo Application Suite - IoT Component - addressed in versions 8.7.21, 8.8.17, 9.0.7
python2-pyOpenSSL - update to 17.5.0-8.3.1
python3-pyOpenSSL - update to 17.5.0-8.3.1
python3-service_identity - update to 18.1.0-3.3.1
NetWorker Management Console (NMC) - update to 19.11
Dell NetWorker Virtual Edition - update to 19.11
Robotic Process Automation for Cloud Pak - update to 21.0.7.8
External References
Related Security Bulletins
- CRLF injection in urllib3 library
- CRLF injection in py3-urllib3 (Alpine package)
- Red Hat Enterprise Linux 8 update for python-urllib3
- Red Hat Enterprise Linux 8 update for the python27:2.7 module
- SUSE update for aws-cli, python-boto3, python-botocore, python-service_identity, python-trustme, python-urllib3
- SUSE update for python-urllib3
- Red Hat Enterprise Linux for Scientific Computing 7 update for python
- Multiple vulnerabilities in Oracle Linux
- CentOS 7 update for python
- Multiple vulnerabilities in IBM Cloud Pak for Security
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.3
- Multiple vulnerabilities in OpenShift Container Platform 3.11
- Multiple vulnerabilities in Dell xDoctor4ECS
- Multiple vulnerabilities in IBM Security Guardium
- Multiple vulnerabilities in Dell XtremIO X2
- CRLF injection in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Cloud Pak for Data Scheduling
- Multiple vulnerabilities in IBM Spectrum Symphony
- CRLF injection in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak for Data System
- Multiple vulnerabilities in Dell Networking OS10
- Multiple vulnerabilities in IBM SOAR QRadar Plugin App
- Multiple vulnerabilities in Dell SmartFabric OS10
- Multiple vulnerabilities in Dell NetWorker Virtual Edition and Dell NetWorker Management Console
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in QRadar Incident Forensics
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 3.11
- Multiple vulnerabilities in OpenShift Virtualization 4.8
- Multiple vulnerabilities in OpenShift Virtualization 2.6
- PowerProtect Data Protection software update for third-party components
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Multiple vulnerabilities in IBM Process Mining
- Ubuntu update for python-urllib3
- Fedora EPEL 7 update for python3-urllib3
- Splunk User Behavior Analytics (UBA) update for third-party components
- Dell RecoverPoint for Virtual Machines update for third-party components