CVE Vulnerabilities

CVE-2020-27619

Published: Oct 22, 2020 | Modified: Feb 03, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.

Affected Software

Name Vendor Start Version End Version
Python Python 3.0.0 (including) 3.6.13 (excluding)
Python Python 3.7.0 (including) 3.7.10 (excluding)
Python Python 3.8.0 (including) 3.8.7 (excluding)
Python Python 3.9.0 (including) 3.9.1 (excluding)

References