Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-01-30T00:00:00
Updated: 2024-08-04T10:03:45.890Z
Reserved: 2020-01-30T00:00:00
Link: CVE-2020-8492
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-01-30T19:15:12.103
Modified: 2024-11-21T05:38:56.167
Link: CVE-2020-8492
Redhat