← Back

CVE-2022-0391

nvd nist
Published: Feb 9, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

Affected (21)

Show all products
1 product
Python
6 products
Active Iq Unified Manager
Hci
Hci Compute Node
1 product
Fedora
2 products
Http Server
Zfs Storage Appliance Kit
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Python
Before 3.6.14
From 3.7.0 to 3.7.11
From 3.8.0 to 3.8.11
From 3.9.0 to 3.9.5
Version 3.10.0 alpha1
Version 3.10.0 alpha2
Version 3.10.0 alpha3
Version 3.10.0 alpha4
Version 3.10.0 alpha5
Version 3.10.0 alpha6
Configuration B
6 vulnerable
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 34
Version 35
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 8.8

References (16)

Source: secalert@redhat.com
ExploitIssue TrackingPatchVendor Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.