cbcvebase.
CVE-2019-9948
published 2019-03-23

CVE-2019-9948: urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist…

critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianpython2.7< python2.7 2.7.16-2 (bullseye)python2.7 2.7.16-2 (bullseye)
fedoraprojectfedora
fedoraprojectfedora
opensuseleap
opensuseleap
pythonpython>= 2.0 < 2.7.172.7.17
pythonpython>= 3.5.0 < 3.5.83.5.8
pythonpython>= 3.6.0 < 3.6.93.6.9
pythonpython>= 3.7.0 < 3.7.43.7.4
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_eus

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
osv9.1CRITICAL