CVE Vulnerabilities

CVE-2019-11236

Improper Neutralization of CRLF Sequences ('CRLF Injection')

Published: Apr 15, 2019 | Modified: Nov 21, 2024
CVSS 3.x
6.1
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.

Weakness

The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

Affected Software

NameVendorStart VersionEnd Version
Urllib3Python*1.24.2 (including)
Red Hat Ansible Tower 3.5 for RHEL 7RedHatansible-tower-35/ansible-tower:3.5.6-1*
Red Hat Ansible Tower 3.6 for RHEL 7RedHatansible-tower-36/ansible-tower:3.6.4-1*
Red Hat Enterprise Linux 7RedHatpython-urllib3-0:1.10.2-7.el7*
Red Hat Enterprise Linux 7RedHatpython-pip-0:9.0.3-7.el7_7*
Red Hat Enterprise Linux 7RedHatpython-virtualenv-0:15.1.0-4.el7_7*
Red Hat Enterprise Linux 7RedHatpython-pip-0:9.0.3-7.el7_8*
Red Hat Enterprise Linux 7RedHatpython-virtualenv-0:15.1.0-4.el7_8*
Red Hat Enterprise Linux 8RedHatpython27:2.7-8010020190903182548.51c94b97*
Red Hat Enterprise Linux 8RedHatpython27:2.7-8020020200117110429.90f98d4f*
Red Hat Enterprise Linux 8RedHatpython-pip-0:9.0.3-16.el8*
Red Hat Enterprise Linux 8RedHatpython-urllib3-0:1.24.2-2.el8*
Red Hat Enterprise Linux 8RedHatpython-pip-0:9.0.3-16.el8*
Red Hat OpenShift Container Platform 4.3RedHatpython-urllib3-0:1.24.3-1.el7*
Red Hat OpenShift Container Platform 4.4RedHatpython-urllib3-0:1.24.3-1.el7*
Python-urllib3Ubuntubionic*
Python-urllib3Ubuntucosmic*
Python-urllib3Ubuntudevel*
Python-urllib3Ubuntudisco*
Python-urllib3Ubuntuesm-infra-legacy/trusty*
Python-urllib3Ubuntuesm-infra/bionic*
Python-urllib3Ubuntuesm-infra/xenial*
Python-urllib3Ubuntutrusty*
Python-urllib3Ubuntutrusty/esm*
Python-urllib3Ubuntuupstream*
Python-urllib3Ubuntuxenial*

Potential Mitigations

References