[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253928

 
 

909

 
 

198006

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2020-1389 --- python-pip python2-pip python3-pip

ID: oval:org.secpod.oval:def:1700300Date: (C)2020-02-11   (M)2024-05-22
Class: PATCHFamily: unix




In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter. The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument

Platform:
Amazon Linux 2
Product:
python-pip
python2-pip
python3-pip
Reference:
ALAS2-2020-1389
CVE-2019-11236
CVE-2019-11324
CVE    2
CVE-2019-11236
CVE-2019-11324

© SecPod Technologies