安全公告详情

NS-SA-2020-0118

2020-12-08 09:15:39

简介

important: python-virtualenv/python-twisted-web security update

严重级别

important

主题

An update for python-virtualenv/python-twisted-web is now available for NewStart CGSL MAIN 5.05/CGSL CORE 5.05.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

python-virtualenv: virtualenv is a tool to create isolated Python environments. virtualenv is a successor to workingenv, and an extension of virtual-python. It is written by Ian Bicking, and sponsored by the Open Planning Project. It is licensed under an MIT-style permissive license.
python-twisted-web: Twisted is an event-based framework for internet applications. Twisted Web is a complete web server, aimed at hosting web applications using Twisted and Python, but fully able to serve static pages too.


Security Fix(es):
python-virtualenv: In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.(CVE-2019-11236)
python-virtualenv: b3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.(CVE-2018-20060)
python-virtualenv: A credentials-exposure flaw was found in python-requests, where if a request with authentication is redirected (302) from an HTTPS endpoint to an HTTP endpoint on the same host, the Authorization header is not stripped and the credentials can be read in plain text. A man-in-the-middle attacker could exploit this flaw to obtain a user's valid credentials.(CVE-2018-18074)
python-virtualenv: bugfix
python-twisted-web: In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.(CVE-2019-12387)
python-twisted-web: A flaw was found in python-twisted-web, where it does not correctly process HTTP requests, accepting requests with more than one Content-Length header. When the requests sent from and to the python-twisted-web are processed by another component that correctly processes HTTP requests, for example, a proxy, back-end, or web application firewall, a remote attacker can use this flaw to perform an HTTP request smuggling attack. This flaw impacts the system differently based on the type of application and the infrastructure.(CVE-2020-10108)
python-twisted-web: A flaw was found in python-twisted-web, where it does not correctly process HTTP requests with both Content-Length and Transfer-Encoding headers. When the requests sent from and to the python-twisted-web are processed by another component that correctly processes HTTP requests, for example, a proxy, back-end, or web application firewall, a remote attacker can use this flaw to perform an HTTP request smuggling attack. This flaw impacts the system differently based on the type of application and the infrastructure.(CVE-2020-10109)
python-twisted-web: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 5.05.F9B3.

影响组件

  • python-virtualenv
  • python-twisted-web

影响产品

  • CGSL MAIN 5.05
  • CGSL CORE 5.05

更新包

{"fix":[{"product":"CGSL MAIN 5.05","pkgs":[{"binary":["python-virtualenv-15.1.0-4.el7_7.noarch.rpm"],"source":"python-virtualenv-15.1.0-4.el7_7.src.rpm"},{"binary":["python-twisted-web-12.1.0-7.el7_8.x86_64.rpm"],"source":"python-twisted-web-12.1.0-7.el7_8.src.rpm"}]},{"product":"CGSL CORE 5.05","pkgs":[{"binary":["python-virtualenv-15.1.0-4.el7_7.noarch.rpm"],"source":"python-virtualenv-15.1.0-4.el7_7.src.rpm"},{"binary":["python-twisted-web-12.1.0-7.el7_8.x86_64.rpm"],"source":"python-twisted-web-12.1.0-7.el7_8.src.rpm"}]}]}

CVE

参考