CVE-2021-3733
published 2022-03-10CVE-2021-3733: There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects…
medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pypy3 | < pypy3 7.3.5+dfsg-2 (bookworm) | pypy3 7.3.5+dfsg-2 (bookworm) |
| debian | python2.7 | < pypy3 7.3.5+dfsg-2 (bookworm) | pypy3 7.3.5+dfsg-2 (bookworm) |
| debian | python3.9 | < pypy3 7.3.5+dfsg-2 (bookworm) | pypy3 7.3.5+dfsg-2 (bookworm) |
| fedoraproject | extra_packages_for_enterprise_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_python2_2.7.18-10_on_cbl_mariner_1.0 | — | — |
| python | python | < 3.6.14 | 3.6.14 |
| python | python | — | — |
| python | python | — | — |
| python | python | >= 3.7.0 < 3.7.11 | 3.7.11 |
| python | python | >= 3.8.0 < 3.8.10 | 3.8.10 |
| python | python | >= 3.9.0 < 3.9.5 | 3.9.5 |
| redhat | codeready_linux_builder | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems | — | — |
| redhat | codeready_linux_builder_for_power_little_endian | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_power_little_endian | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.6HIGH