← Back to CVE List
Vulnerability Intelligence Report

CVE-2019-9636

Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a given hostname). The components are: urllib.parse.urlsplit, urllib.parse.urlparse. The attack vector is: A specially crafted URL could be incorrectly parsed to locate cookies or authentication data and send that information to a different host than when parsed correctly. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.7, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.3, v3.7.3rc1, v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:8.81%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
python python all
fedoraproject fedora 28, 29, 30, 31
opensuse leap 15.0, 15.1, 42.3
debian debian_linux 8.0, 9.0
canonical ubuntu_linux 12.04, 14.04, 16.04, 18.04, 19.04
redhat openshift_container_platform 3.11
redhat enterprise_linux 7.5, 8.0, 7.0
redhat enterprise_linux_desktop 6.0
redhat enterprise_linux_eus 7.5, 8.1, 8.2, 8.4, 8.6
redhat enterprise_linux_server 6.0
redhat enterprise_linux_server_aus 7.4, 8.2, 8.4
redhat enterprise_linux_server_eus 5.6
redhat enterprise_linux_server_tus 7.4, 8.2, 8.4, 8.6
redhat enterprise_linux_workstation 6.0
redhat virtualization 4.0
oracle sun_zfs_storage_appliance_kit 8.8.6

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
8.811%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2019-03-08T00:00:00
Published2019-03-08T21:00:00
Patch Date2019-03-08
Last Updated2024-08-04T21:54:45

LINK COPIED TO CLIPBOARD