CRLF injection in Python - CVE-2020-26116
Published: September 27, 2020 / Updated: July 20, 2022
Vulnerability details
The vulnerability allows a remote attacker to inject arbitrary data in server response.
The vulnerability exists due to insufficient validation of attacker-supplied data in "http.client". A remote attacker can pass specially crafted data to the application containing CR-LF characters and modify application behavior.
Affected software
ClevOS
Arch Linux
Gentoo Linux
Amazon Linux AMI
CentOS
Oracle Linux
Red Hat Enterprise Linux for Scientific Computing
Fedora
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - TUS
Ubuntu
Tanzu Greenplum for Kubernetes
Platform Automation Toolkit
XtremIO X2
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Red Hat OpenShift Jaeger
Red Hat Advanced Cluster Management for Kubernetes
VMware Tanzu Application Service for VMs
Isolation Segment
IBM Robotic Process Automation
VMware Tanzu Operations Manager
OpenShift Virtualization
python3 (Red Hat package)
python3.8 (Ubuntu package)
python3.5-minimal (Ubuntu package)
python3.5 (Ubuntu package)
python3.7-minimal (Ubuntu package)
python3.7 (Ubuntu package)
python3.6-minimal (Ubuntu package)
python3.11 (Ubuntu package)
python3.6 (Ubuntu package)
python3.11-minimal (Ubuntu package)
python3.9-minimal (Ubuntu package)
python3.9 (Ubuntu package)
python3.8-minimal (Ubuntu package)
python2.7 (Ubuntu package)
python2.7-minimal (Ubuntu package)
python2
python27
python2.7
python3.4 (Ubuntu package)
python3.4-minimal (Ubuntu package)
python34
python3-libs
python3-idle
platform-python-devel
platform-python-debug
platform-python
python3-test
python3-tkinter
mingw-python3
python3.10-minimal (Ubuntu package)
python3.10 (Ubuntu package)
python3.12-minimal (Ubuntu package)
python3.12 (Ubuntu package)
Red Hat OpenShift Container Platform
Web Terminal
Junos Space Security Director
How to mitigate CVE-2020-26116
Tanzu Greenplum for Kubernetes - update to 2.0.0
Cloud Pak for Security (CP4S) - update to 1.8.0.0
Red Hat OpenShift Jaeger - addressed in versions 1.17.9, 1.20.4
Red Hat Advanced Cluster Management for Kubernetes - update to 2.3.12
VMware Tanzu Application Service for VMs - addressed in versions 2.7.27, 2.8.21, 2.9.15, 2.10.7
Isolation Segment - addressed in versions 2.7.26, 2.8.20, 2.9.14, 2.10.6
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.9.12, 2.10.3
python3 (Red Hat package) - addressed in versions 3.6.8-24.el8_2, 3.6.8-37.el8
Red Hat OpenShift Container Platform - update to 3.11.784
Platform Automation Toolkit - addressed in versions 4.3.21, 4.4.13, 5.0.7
python3.8 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.8.0-3~18.04.1, 3.8.10-0ubuntu1~20.04.10
python3.5-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.5.2-2ubuntu0~16.04.12
python3.5 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 3.5.2-2ubuntu0~16.04.12
python3.7-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.7.5-2~18.04.4
python3.7 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.7.5-2~18.04.4
python3.6-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.6.9-1~18.04ubuntu1.3
python3.11 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.11.6-3ubuntu0.1
python3.6 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.6.9-1~18.04ubuntu1.3
python3.11-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.11.6-3ubuntu0.1
python3.9-minimal (Ubuntu package) - update to Ubuntu Pro
python3.9 (Ubuntu package) - update to Ubuntu Pro
python3.8-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.8.0-3~18.04.1, 3.8.10-0ubuntu1~20.04.10
Web Terminal - update to 1.3
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
python2.7 (Ubuntu package) - addressed in versions 2.7.3-0ubuntu3.19, 2.7.6-8ubuntu0.6+esm7, 2.7.12-1ubuntu0~16.04.13, 2.7.17-1~18.04ubuntu1.2, 2.7.18-1~20.04.1
python2.7-minimal (Ubuntu package) - addressed in versions 2.7.3-0ubuntu3.19, 2.7.6-8ubuntu0.6+esm7, 2.7.12-1ubuntu0~16.04.13, 2.7.17-1~18.04ubuntu1.2, 2.7.18-1~20.04.1
python2 - update to 2.7.18-6.fc31
python27 - update to 2.7.18-6.fc32
python2.7 - update to 2.7.18-6.fc33
python3.4 (Ubuntu package) - update to 3.4.3-1ubuntu1~14.04.7+esm8
python3.4-minimal (Ubuntu package) - update to 3.4.3-1ubuntu1~14.04.7+esm8
python34 - addressed in versions 3.4.10-7.el7, 3.4.10-11.fc32
python3-libs - update to 3.6.8-24.0.1
python3-idle - update to 3.6.8-24.0.1
platform-python-devel - update to 3.6.8-24.0.1
platform-python-debug - update to 3.6.8-24.0.1
platform-python - update to 3.6.8-24.0.1
python3-test - update to 3.6.8-24.0.1
python3-tkinter - update to 3.6.8-24.0.1
mingw-python3 - addressed in versions 3.8.3-4.fc32, 3.8.3-5.fc32, 3.8.3-7.fc32
python3.10-minimal (Ubuntu package) - update to 3.10.12-1~22.04.4
python3.10 (Ubuntu package) - update to 3.10.12-1~22.04.4
python3.12-minimal (Ubuntu package) - update to 3.12.0-1ubuntu0.1
python3.12 (Ubuntu package) - update to 3.12.0-1ubuntu0.1
XtremIO X2 - update to 6.4.1-11
IBM Qradar SIEM - update to 7.5.0 Update Pack 6
IBM Robotic Process Automation - update to 21.0.5
Junos Space Security Director - update to 24.1R3
External References
- http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00027.html
- https://bugs.python.org/issue39603
- https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BW4GCLQISJCOEGQNIMVUZDQMIY6RR6CC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HDQ2THWU4GPV4Y5H5WW5PFMSWXL2CRFD/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JWMAVY4T4257AZHTF2RZJKNJNSJFY24O/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QOX7DGMMWWL6POCRYGAUCISOLR2IG3XV/
- https://python-security.readthedocs.io/vuln/http-header-injection-method.html
- https://security.netapp.com/advisory/ntap-20201023-0001/
- https://usn.ubuntu.com/4581-1/
Related Security Bulletins
- Multiple vulnerabilities in Python
- Amazon Linux AMI update for python27, python34, python35
- CRLF injection in VMware Products
- Gentoo update for Python
- Arch Linux update for python2
- Red Hat Enterprise Linux 8 update for python3
- Red Hat Enterprise Linux 8 update for the python27:2.7 module
- Red Hat Enterprise Linux 8 update for the python38:3.8 module
- Multiple vulnerabilities in Red Hat OpenShift Jaeger
- Multiple vulnerabilities in Red Hat OpenShift Jaeger
- Red Hat Enterprise Linux 8.2 update for python3
- Multiple vulnerabilities in Red Hat Web Terminal
- Ubuntu update for python2.7
- Red Hat Enterprise Linux for Scientific Computing 7 update for python
- Multiple vulnerabilities in Oracle Linux
- CentOS 7 update for python
- Multiple vulnerabilities in IBM Cloud Pak for Security
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.3
- Multiple vulnerabilities in OpenShift Container Platform 3.11
- ClevOS update for IBM Cloud Object Storage Systems
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Dell XtremIO X2
- Ubuntu update for python3.10
- Multiple vulnerabilities in OpenShift Virtualization 4.8
- Multiple vulnerabilities in OpenShift Virtualization 2.6
- Anolis OS update for python3
- Ubuntu update for python2.7
- Fedora EPEL 7 update for python34
- Fedora 33 update for python2.7
- Fedora 32 update for python34
- Fedora 32 update for python27
- Fedora 31 update for python2
- Fedora 32 update for mingw-python3
- Fedora 32 update for mingw-python3
- Fedora 32 update for mingw-python3
- Multiple vulnerabilities in Junos Space Security Director Policy Enforcer module