Bug 1812095 (CVE-2020-7212)
| Summary: | CVE-2020-7212 python-urllib3: inefficient algorithm allows a DoS (CPU consumption) in _encode_invalid_chars function in util/url.py | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Guilherme de Almeida Suckevicz <gsuckevi> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED NOTABUG | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | apevec, aurelien, bbuckingham, bcourt, bdettelb, bkearney, bmontgom, btotty, cstratak, dbecker, eparis, hhorak, hhudgeon, hvyas, infra-sig, jburrell, jeremy, jjoyce, jokerman, jorton, jschluet, jschorr, jshepherd, kbasil, lhh, lpeer, lzap, mburns, mmccune, nstielau, puebele, python-maint, rchan, rhos-maint, rjerrido, sclewis, slinaber, sokeeffe, sponnaga, tomckay, torsava, vbellur |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | urllib3 1.25.8 | Doc Type: | If docs needed, set a value |
| Doc Text: |
If provided a specially crafted URL, urllib3 could be made to encode it using an O(N^2) algorithm, when an approximately O(N) one was possible.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2020-03-30 05:18:20 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1812102 | ||
| Bug Blocks: | 1812101 | ||
|
Description
Guilherme de Almeida Suckevicz
2020-03-10 14:14:24 UTC
Created python-urllib3 tracking bugs for this issue: Affects: fedora-all [bug 1812102] OpenShift Container Platform uses urllib3-1.21.1-1, which does not include the vulnerable _encode_invalid_chars function. Note: flawed code was added in urllib3 1.25.2, Pull: https://github.com/urllib3/urllib3/pull/1586 Commit: https://github.com/urllib3/urllib3/commit/a74c9cfbaed9f811e7563cfc3dce894928e0221a Statement: Red Hat Product Security does not consider this to be a vulnerability. The choice of an inefficient algorithm could cause a little more CPU time to be used than the alternative, however the difference in practice is not sufficient to cause a meaningful or even noticeable impact on the application. |