cbcvebase.
CVE-2020-11078
published 2020-05-20

CVE-2020-11078: In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send…

PriorityP338medium6.8CVSS 3.1
AVNACHPRNUINSCCNIHAN
EPSS
2.59%
83.8th percentile
In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability impacts software that uses httplib2 with uri constructed by string concatenation, as opposed to proper urllib building with escaping. This has been fixed in 0.18.0.

Affected

7 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianpython-httplib2< python-httplib2 0.18.1-1 (bookworm)python-httplib2 0.18.1-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
httplib2httplib2< 0.81.00.81.0
httplib2httplib2>= 0 < 0.18.00.18.0
httplib2_projecthttplib2< 0.18.00.18.0

CVSS provenance

nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.