vulnerability

Ubuntu: (Multiple Advisories) (CVE-2020-8492): Python vulnerabilities

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:C)
Published
Jan 30, 2020
Added
Apr 22, 2020
Modified
Aug 18, 2025

Description

Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.

Solutions

ubuntu-pro-upgrade-libpython3-7-stdlibubuntu-pro-upgrade-libpython3-8-stdlibubuntu-pro-upgrade-python2-7ubuntu-pro-upgrade-python2-7-minimalubuntu-pro-upgrade-python3-4ubuntu-pro-upgrade-python3-4-minimalubuntu-pro-upgrade-python3-5ubuntu-pro-upgrade-python3-5-minimalubuntu-pro-upgrade-python3-6ubuntu-pro-upgrade-python3-6-minimalubuntu-pro-upgrade-python3-7ubuntu-pro-upgrade-python3-7-minimalubuntu-pro-upgrade-python3-8ubuntu-pro-upgrade-python3-8-minimal

References

    Title
    NEW

    Explore Exposure Command

    Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.