HTTP Response Splitting Affecting python2-pymongo-gridfs package, versions <0:3.6.1-11.module+el8.1.0+3446+c3d52da3


Severity

Recommended
0.0
medium
0
10

Based on CentOS security rating.

Threat Intelligence

EPSS
0.2% (58th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CENTOS8-PYTHON2PYMONGOGRIDFS-2104463
  • published26 Jul 2021
  • disclosed10 Feb 2020

Introduced: 10 Feb 2020

CVE-2020-26116  (opens in a new tab)
CWE-113  (opens in a new tab)

How to fix?

Upgrade Centos:8 python2-pymongo-gridfs to version 0:3.6.1-11.module+el8.1.0+3446+c3d52da3 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream python2-pymongo-gridfs package and not the python2-pymongo-gridfs package as distributed by Centos. See How to fix? for Centos:8 relevant fixed versions and status.

http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.

References

CVSS Scores

version 3.1