CRLF injection in Python - CVE-2022-0391
Published: March 29, 2022
Vulnerability details
The vulnerability allows a remote attacker to inject arbitrary data in server response.
The vulnerability exists due to insufficient validation of attacker-supplied data within the urllib.parse module in Python. A remote attacker can pass specially crafted data to the application containing CR-LF characters and modify application behavior.
Affected software
Amazon Linux AMI
Gentoo Linux
SUSE Manager Server
SUSE Manager Proxy
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Oracle Solaris
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Workstation Extension
Ubuntu
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module Python3
openEuler
Fedora
cflinuxfs3
SmartFabric OS10
IBM Netezza for Cloud Pak for Data
PowerStore X
PowerStore T
EMC ECS
Enterprise SONiC
XtremIO X2
Dell Data Protection Central
OpenShift sandboxed containers
OpenShift Virtualization
Red Hat Software Collections
Voice Gateway
QRadar Suite
IBM Security SOAR
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Dell Secure Connect Gateway
OpenShift Logging
Red Hat OpenShift distributed tracing (RHOSDT)
IBM Cloud Transformation Advisor
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Elastic Storage System
IBM Spectrum Protect Plus
python27-python (Red Hat package)
python27-python-pip (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
python3.11 (Ubuntu package)
python3.11-minimal (Ubuntu package)
python3.5-minimal (Ubuntu package)
python3.5 (Ubuntu package)
python3.8 (Ubuntu package)
python3.8-minimal (Ubuntu package)
python3.9 (Ubuntu package)
python3.9-minimal (Ubuntu package)
python3.7-minimal (Ubuntu package)
python3.6 (Ubuntu package)
python3.6-minimal (Ubuntu package)
python3.7 (Ubuntu package)
python38-wcwidth
python38-PyMySQL
python38-pluggy
python38-Cython
python38-wheel
python38-wheel-wheel
python38-markupsafe
python38-asn1crypto
python38-atomicwrites
python38-scipy
python38-pysocks
python38-py
python38-six
python38-cffi
python38-numpy
python38-numpy-f2py
python38-numpy-doc
python38-urllib3
python38-pyparsing
python38-babel
python2.7-minimal (Ubuntu package)
python2.7 (Ubuntu package)
python2.7
python-curses
libpython2_7-1_0
python-base-debugsource
python-base-debuginfo-32bit
python-base-debuginfo
python-base-32bit
python-base
python-32bit
python
libpython2_7-1_0-debuginfo-32bit
libpython2_7-1_0-debuginfo
libpython2_7-1_0-32bit
python-curses-debuginfo
python-debuginfo
python-debuginfo-32bit
python-debugsource
python-demo
python-devel
python-gdbm
python-gdbm-debuginfo
python-idle
python-tk
python-tk-debuginfo
python-xml
python-xml-debuginfo
python-doc
python-doc-pdf
python38-cryptography
python38-psycopg2-tests
python38-psycopg2-doc
python38-psycopg2
python38-idna
python38-jinja2
python38-pycparser
python38-requests
python38-chardet
python3.4 (Ubuntu package)
python3.4-minimal (Ubuntu package)
python3-base-debuginfo
python3-base-debugsource
python3-devel
python3-devel-debuginfo
libpython3_4m1_0
libpython3_4m1_0-debuginfo
python3-base
libpython3_4m1_0-32bit
libpython3_4m1_0-debuginfo-32bit
python3-base-debuginfo-32bit
python3-dbm-debuginfo
python3-debuginfo
python3-debugsource
python3-tk-debuginfo
python3-dbm
python3-curses
python3-tk
python3
python3-curses-debuginfo
python3 (Red Hat package)
python3-debug
python3-help
python38-test
python38
python38-tkinter
python38-debug
python38-devel
python38-idle
python38-libs
python38-rpm-macros
mingw-python3
python3.10 (Ubuntu package)
python3.10-minimal (Ubuntu package)
python38-ply
python3.12-minimal (Ubuntu package)
python3.12 (Ubuntu package)
python38-lxml
python38-pytest
python38-mod_wsgi
python38-pyyaml
python38-psutil
python38-more-itertools
python38-packaging
python38-attrs
python38-pip
python38-pip-wheel
python38-setuptools
python38-setuptools-wheel
python38-pytz
Red Hat OpenShift Container Platform
HPE Moonshot 1500 Chassis Manager
IBM Tivoli Application Dependency Discovery Manager
IBM Security Verify Access
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
IBM Cognos Analytics
How to mitigate CVE-2022-0391
cflinuxfs3 - update to 0.279.0
OpenShift sandboxed containers - update to 1.3.1
Voice Gateway - update to 1.0.8.12
QRadar Suite - update to 1.10.17.0
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.4.6, 2.5.3, 2.6.2
python27-python (Red Hat package) - update to 2.7.18-4.el7
Red Hat Advanced Cluster Security for Kubernetes - update to 3.72
Red Hat OpenShift Container Platform - update to 4.11.5
Dell Secure Connect Gateway - update to 5.12.00.10
OpenShift Logging - update to 5.3.12
python27-python-pip (Red Hat package) - update to 8.1.2-7.el7
IBM Security Verify Access - update to 10.0.5.0 FP001
SmartFabric OS10 - update to 10.5.4.11
IBM Netezza for Cloud Pak for Data - update to 11.2.1.6
IBM Security SOAR - update to 45.0
python3.11 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.11.6-3ubuntu0.1
python3.11-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.11.6-3ubuntu0.1
python3.5-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.5.2-2ubuntu0~16.04.13
python3.5 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 3.5.2-2ubuntu0~16.04.13
python3.8 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.8.10-0ubuntu1~20.04.4, 3.8.10-0ubuntu1~20.04.10
python3.8-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.8.10-0ubuntu1~20.04.4, 3.8.10-0ubuntu1~20.04.10
python3.9 (Ubuntu package) - update to Ubuntu Pro
python3.9-minimal (Ubuntu package) - update to Ubuntu Pro
python3.7-minimal (Ubuntu package) - update to Ubuntu Pro
python3.6 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.6.9-1~18.04ubuntu1.7
python3.6-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.6.9-1~18.04ubuntu1.7
python3.7 (Ubuntu package) - update to Ubuntu Pro
python38-wcwidth - update to 0.1.7-16
python38-PyMySQL - update to 0.10.1-1
python38-pluggy - update to 0.13.0-3
python38-Cython - update to 0.29.14-4
python38-wheel - update to 0.33.6-6
python38-wheel-wheel - update to 0.33.6-6
python38-markupsafe - update to 1.1.1-6
python38-asn1crypto - update to 1.2.0-3
python38-atomicwrites - update to 1.3.0-8
python38-scipy - update to 1.3.1-4
python38-pysocks - update to 1.7.1-4
python38-py - update to 1.8.0-8
Cloud Pak for Security (CP4S) - update to 1.10.10.0
python38-six - update to 1.12.0-10
python38-cffi - update to 1.13.2-3
python38-numpy - update to 1.17.3-6
python38-numpy-f2py - update to 1.17.3-6
python38-numpy-doc - update to 1.17.3-6
python38-urllib3 - update to 1.25.7-5
python38-pyparsing - update to 2.4.5-3
Red Hat OpenShift distributed tracing (RHOSDT) - update to 2.6.0
python38-babel - update to 2.7.0-11
python2.7-minimal (Ubuntu package) - update to 2.7.17-1~18.04ubuntu1.7
python2.7 (Ubuntu package) - update to 2.7.17-1~18.04ubuntu1.7
python2.7 - addressed in versions 2.7.18-20.fc34, 2.7.18-20.fc35, 2.7.18-20.fc37
python-curses - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.1
libpython2_7-1_0 - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.2
python-base-debugsource - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.2
python-base-debuginfo-32bit - update to 2.7.18-33.8.1
python-base-debuginfo - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.2
python-base-32bit - update to 2.7.18-33.8.1
python-base - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.2
python-32bit - update to 2.7.18-33.8.1
python - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.1
libpython2_7-1_0-debuginfo-32bit - update to 2.7.18-33.8.1
libpython2_7-1_0-debuginfo - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.2
libpython2_7-1_0-32bit - update to 2.7.18-33.8.1
python-curses-debuginfo - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.1
python-debuginfo - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.1
python-debuginfo-32bit - update to 2.7.18-33.8.1
python-debugsource - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.1
python-demo - update to 2.7.18-33.8.1
python-devel - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.2
python-gdbm - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.1
python-gdbm-debuginfo - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.1
python-idle - update to 2.7.18-33.8.1
python-tk - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.1
python-tk-debuginfo - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.1
python-xml - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.2
python-xml-debuginfo - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.2
python-doc - update to 2.7.18-33.8.1
python-doc-pdf - update to 2.7.18-33.8.1
python38-cryptography - update to 2.8-3
python38-psycopg2-tests - update to 2.8.4-4
python38-psycopg2-doc - update to 2.8.4-4
python38-psycopg2 - update to 2.8.4-4
python38-idna - update to 2.8-6
python38-jinja2 - update to 2.10.3-5
python38-pycparser - update to 2.19-3
python38-requests - update to 2.22.0-9
python38-chardet - update to 3.0.4-19
PowerStore X - update to 3.2.1.0-1989710
PowerStore T - update to 3.2.1.0-1989710
python3.4 (Ubuntu package) - update to 3.4.3
python3.4-minimal (Ubuntu package) - update to 3.4.3-1ubuntu1~14.04.7
python3-base-debuginfo - update to 3.4.10-25.85.1
python3-base-debugsource - update to 3.4.10-25.85.1
python3-devel - update to 3.4.10-25.85.1
python3-devel-debuginfo - update to 3.4.10-25.85.1
libpython3_4m1_0 - update to 3.4.10-25.85.1
libpython3_4m1_0-debuginfo - update to 3.4.10-25.85.1
python3-base - update to 3.4.10-25.85.1
libpython3_4m1_0-32bit - update to 3.4.10-25.85.1
libpython3_4m1_0-debuginfo-32bit - update to 3.4.10-25.85.1
python3-base-debuginfo-32bit - update to 3.4.10-25.85.1
python3-dbm-debuginfo - update to 3.4.10-25.85.2
python3-debuginfo - update to 3.4.10-25.85.2
python3-debugsource - update to 3.4.10-25.85.2
python3-tk-debuginfo - update to 3.4.10-25.85.2
python3-dbm - update to 3.4.10-25.85.2
python3-curses - update to 3.4.10-25.85.2
python3-tk - update to 3.4.10-25.85.2
python3 - update to 3.4.10-25.85.2
python3-curses-debuginfo - update to 3.4.10-25.85.2
python3 (Red Hat package) - update to 3.6.8-47.el8_6
EMC ECS - update to 3.7.0.2
python3-devel - update to 3.7.9-20
python3 - update to 3.7.9-20
python3-debuginfo - update to 3.7.9-20
python3-debugsource - update to 3.7.9-20
python3-debug - update to 3.7.9-20
python3-help - update to 3.7.9-20
python38-test - update to 3.8.12-1.0.1
python38 - update to 3.8.12-1.0.1
python38-tkinter - update to 3.8.12-1.0.1
python38-debug - update to 3.8.12-1.0.1
python38-devel - update to 3.8.12-1.0.1
python38-idle - update to 3.8.12-1.0.1
python38-libs - update to 3.8.12-1.0.1
python38-rpm-macros - update to 3.8.12-1.0.1
mingw-python3 - update to 3.9.4-4.fc34
IBM Cloud Transformation Advisor - update to 3.10.1
python3.10 (Ubuntu package) - update to 3.10.12-1~22.04.4
python3.10-minimal (Ubuntu package) - update to 3.10.12-1~22.04.4
python38-ply - update to 3.11-10
python3.12-minimal (Ubuntu package) - update to 3.12.0-1ubuntu0.1
python3.12 (Ubuntu package) - update to 3.12.0-1ubuntu0.1
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
Enterprise SONiC - update to 4.1.2
python38-lxml - update to 4.4.1-7
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.0
python38-pytest - update to 4.6.6-3
python38-mod_wsgi - update to 4.6.8-3
OpenShift Virtualization - addressed in versions 4.11.1, 4.12.0
python38-pyyaml - update to 5.4.1-1
python38-psutil - update to 5.6.4-4
IBM Elastic Storage System - addressed in versions 6.1.2.5, 6.1.5.0
XtremIO X2 - update to 6.4.1-11
python38-more-itertools - update to 7.2.0-5
IBM Qradar SIEM - update to 7.5.0 Update Pack 6
IBM Spectrum Protect Plus - update to 10.1.15.2
IBM Cognos Analytics - addressed in versions 11.1.7.6, 11.2.3
python38-packaging - update to 19.2-3
python38-attrs - update to 19.3.0-3
python38-pip - update to 19.3.1-5
python38-pip-wheel - update to 19.3.1-5
Dell Data Protection Central - update to 19.9
python38-setuptools - update to 41.6.0-5
python38-setuptools-wheel - update to 41.6.0-5
python38-pytz - update to 2019.3-3
External References
- https://bugs.python.org/issue43882
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CSD2YBXP3ZF44E44QMIIAR5VTO35KTRB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UDBDBAU6HUPZHISBOARTXZ5GKHF2VH5U/
- https://security.netapp.com/advisory/ntap-20220225-0009/
Related Security Bulletins
- CRLF injection in Python urllib.parse
- Ubuntu update for python2.7
- Multiple vulnerabilities in cflinuxfs3
- Multiple vulnerabilities in Oracle Solaris
- Red Hat Software Collections update for python27-python and python27-python-pip
- Red Hat Enterprise Linux 8 update for the python38:3.8 and python38-devel:3.8 modules
- Red Hat Enterprise Linux 8 update for the python27:2.7 module
- CRLF injection in IBM Security SOAR
- Amazon Linux AMI update for python27
- CRLF injection in IBM Tivoli Application Dependency Discovery Manager
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- CRLF injection in IBM Netezza for Cloud Pak for Data
- Red Hat Enterprise Linux 8 update for python3
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in Dell Elastic Cloud Storage (ECS)
- Multiple vulnerabilities in OpenShift Logging 5.3
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes (RHACS)
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.5
- Multiple vulnerabilities in Red Hat OpenShift distributed tracing (RHOSDT)
- Multiple vulnerabilities in OpenShift sandboxed containers
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.6
- CRLF injection in IBM Watson Discovery for IBM Cloud Pak for Data
- Multiple vulnerabilities in OpenShift Virtualization 4.11
- Multiple vulnerabilities in IBM Cognos Analytics
- CRLF injection in IBM Elastic Storage System
- Multiple vulnerabilities in OpenShift Virtualization 4.12
- SUSE update for python3
- SUSE update for python
- SUSE update for python
- Multiple vulnerabilities in IBM Security Verify Access
- Gentoo update for Python, PyPy3
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Dell XtremIO X2
- Multiple vulnerabilities in Dell PowerStore Family
- Multiple vulnerabilities in Dell Data Protection Central
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in IBM QRadar Suite software
- Multiple vulnerabilities in Dell EMC Enterprise SONiC
- openEuler update for python3
- Ubuntu update for python3.10
- Multiple vulnerabilities in Dell SmartFabric OS10
- Multiple vulnerabilities in HPE Moonshot 1500 Chassis Manager
- Fedora 34 update for mingw-python3
- Fedora 37 update for python2.7
- Fedora 34 update for python2.7
- Fedora 35 update for python2.7
- Anolis OS update for python38:3.8 module
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Voice Gateway