CRLF injection in Python - CVE-2020-26116

 

CRLF injection in Python - CVE-2020-26116

Published: September 27, 2020 / Updated: July 20, 2022


Vulnerability identifier: #VU48592
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-26116
CWE-ID: CWE-93
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject arbitrary data in server response.

The vulnerability exists due to insufficient validation of attacker-supplied data in "http.client". A remote attacker can pass specially crafted data to the application containing CR-LF characters and modify application behavior.


Affected software

Python
ClevOS
Arch Linux
Gentoo Linux
Amazon Linux AMI
CentOS
Oracle Linux
Red Hat Enterprise Linux for Scientific Computing
Fedora
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - TUS
Ubuntu
Tanzu Greenplum for Kubernetes
Platform Automation Toolkit
XtremIO X2
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Red Hat OpenShift Jaeger
Red Hat Advanced Cluster Management for Kubernetes
VMware Tanzu Application Service for VMs
Isolation Segment
IBM Robotic Process Automation
VMware Tanzu Operations Manager
OpenShift Virtualization
python3 (Red Hat package)
python3.8 (Ubuntu package)
python3.5-minimal (Ubuntu package)
python3.5 (Ubuntu package)
python3.7-minimal (Ubuntu package)
python3.7 (Ubuntu package)
python3.6-minimal (Ubuntu package)
python3.11 (Ubuntu package)
python3.6 (Ubuntu package)
python3.11-minimal (Ubuntu package)
python3.9-minimal (Ubuntu package)
python3.9 (Ubuntu package)
python3.8-minimal (Ubuntu package)
python2.7 (Ubuntu package)
python2.7-minimal (Ubuntu package)
python2
python27
python2.7
python3.4 (Ubuntu package)
python3.4-minimal (Ubuntu package)
python34
python3-libs
python3-idle
platform-python-devel
platform-python-debug
platform-python
python3-test
python3-tkinter
mingw-python3
python3.10-minimal (Ubuntu package)
python3.10 (Ubuntu package)
python3.12-minimal (Ubuntu package)
python3.12 (Ubuntu package)
Red Hat OpenShift Container Platform
Web Terminal
Junos Space Security Director

How to mitigate CVE-2020-26116

Install updates from vendor's website.

Python - addressed in versions 3.5.10, 3.6.12, 3.7.9, 3.8.5
Tanzu Greenplum for Kubernetes - update to 2.0.0
Cloud Pak for Security (CP4S) - update to 1.8.0.0
Red Hat OpenShift Jaeger - addressed in versions 1.17.9, 1.20.4
Red Hat Advanced Cluster Management for Kubernetes - update to 2.3.12
VMware Tanzu Application Service for VMs - addressed in versions 2.7.27, 2.8.21, 2.9.15, 2.10.7
Isolation Segment - addressed in versions 2.7.26, 2.8.20, 2.9.14, 2.10.6
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.9.12, 2.10.3
python3 (Red Hat package) - addressed in versions 3.6.8-24.el8_2, 3.6.8-37.el8
Red Hat OpenShift Container Platform - update to 3.11.784
Platform Automation Toolkit - addressed in versions 4.3.21, 4.4.13, 5.0.7
python3.8 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.8.0-3~18.04.1, 3.8.10-0ubuntu1~20.04.10
python3.5-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.5.2-2ubuntu0~16.04.12
python3.5 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 3.5.2-2ubuntu0~16.04.12
python3.7-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.7.5-2~18.04.4
python3.7 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.7.5-2~18.04.4
python3.6-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.6.9-1~18.04ubuntu1.3
python3.11 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.11.6-3ubuntu0.1
python3.6 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.6.9-1~18.04ubuntu1.3
python3.11-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.11.6-3ubuntu0.1
python3.9-minimal (Ubuntu package) - update to Ubuntu Pro
python3.9 (Ubuntu package) - update to Ubuntu Pro
python3.8-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.8.0-3~18.04.1, 3.8.10-0ubuntu1~20.04.10
Web Terminal - update to 1.3
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
python2.7 (Ubuntu package) - addressed in versions 2.7.3-0ubuntu3.19, 2.7.6-8ubuntu0.6+esm7, 2.7.12-1ubuntu0~16.04.13, 2.7.17-1~18.04ubuntu1.2, 2.7.18-1~20.04.1
python2.7-minimal (Ubuntu package) - addressed in versions 2.7.3-0ubuntu3.19, 2.7.6-8ubuntu0.6+esm7, 2.7.12-1ubuntu0~16.04.13, 2.7.17-1~18.04ubuntu1.2, 2.7.18-1~20.04.1
python2 - update to 2.7.18-6.fc31
python27 - update to 2.7.18-6.fc32
python2.7 - update to 2.7.18-6.fc33
python3.4 (Ubuntu package) - update to 3.4.3-1ubuntu1~14.04.7+esm8
python3.4-minimal (Ubuntu package) - update to 3.4.3-1ubuntu1~14.04.7+esm8
python34 - addressed in versions 3.4.10-7.el7, 3.4.10-11.fc32
python3-libs - update to 3.6.8-24.0.1
python3-idle - update to 3.6.8-24.0.1
platform-python-devel - update to 3.6.8-24.0.1
platform-python-debug - update to 3.6.8-24.0.1
platform-python - update to 3.6.8-24.0.1
python3-test - update to 3.6.8-24.0.1
python3-tkinter - update to 3.6.8-24.0.1
mingw-python3 - addressed in versions 3.8.3-4.fc32, 3.8.3-5.fc32, 3.8.3-7.fc32
python3.10-minimal (Ubuntu package) - update to 3.10.12-1~22.04.4
python3.10 (Ubuntu package) - update to 3.10.12-1~22.04.4
python3.12-minimal (Ubuntu package) - update to 3.12.0-1ubuntu0.1
python3.12 (Ubuntu package) - update to 3.12.0-1ubuntu0.1
XtremIO X2 - update to 6.4.1-11
IBM Qradar SIEM - update to 7.5.0 Update Pack 6
IBM Robotic Process Automation - update to 21.0.5
Junos Space Security Director - update to 24.1R3

External References

Related Security Bulletins