Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html Third Party Advisory
https://bugs.python.org/issue39503 Issue Tracking Vendor Advisory
https://github.com/python/cpython/pull/18284 Patch Third Party Advisory
https://lists.apache.org/thread.html/rdb31a608dd6758c6093fd645aea3fbf022dd25b37109b6aaea5bc0b5%40%3Ccommits.cassandra.apache.org%3E
https://lists.apache.org/thread.html/rfec113c733162b39633fd86a2d0f34bf42ac35f711b3ec1835c774da%40%3Ccommits.cassandra.apache.org%3E
https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WOKDEXLYW5UQ4S7PA7E37IITOC7C56J/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A5NSAX4SC3V64PGZUPH7PRDLSON34Q5A/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APGWEMYZIY5VHLCSZ3HD67PA5Z2UQFGH/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UESGYI5XDAHJBATEZN3MHNDUBDH47AS6/
https://python-security.readthedocs.io/vuln/urllib-basic-auth-regex.html Exploit Third Party Advisory
https://security.gentoo.org/glsa/202005-09 Third Party Advisory
https://security.netapp.com/advisory/ntap-20200221-0001/ Third Party Advisory
https://usn.ubuntu.com/4333-1/ Third Party Advisory
https://usn.ubuntu.com/4333-2/ Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-01-30T00:00:00

Updated: 2023-05-24T00:00:00

Reserved: 2020-01-30T00:00:00


Link: CVE-2020-8492

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2020-01-30T19:15:12.103

Modified: 2023-11-07T03:26:36.510


Link: CVE-2020-8492

JSON object: View

cve-icon Redhat Information

No data.

CWE