Vulnérabilité · NVD
CVE-2021-3733
EN There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.
Voir le vecteur CVSS brut
Apps suivies liées à cette CVE
Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.
NVD référence 20 produits distincts pour cette CVE — seuls ceux suivis par Scout (apps des catalogues mobile et desktop) sont listés ci-dessus. Bibliothèques, serveurs et produits hors périmètre n'apparaissent pas. Liste complète sur NVD ↗
Configurations CPE vulnérables (5)
| Vendor | Produit | Plateforme | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | <3.6.14 | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | ≥3.7.0 <3.7.11 | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | ≥3.8.0 <3.8.10 | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | ≥3.9.0 <3.9.5 | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | — | cpe:2.3:a:python:python:3.10.0:-:*:*:*:*:*:* |