Description
CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.
Remediation
References
Related Vulnerabilities
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2016-3734)
Django Improper Validation of Specified Quantity in Input Vulnerability (CVE-2024-41991)
Oracle HTTP Server Improper Input Validation Vulnerability (CVE-2020-29507)
Atlassian Jira CVE-2020-36235 Vulnerability (CVE-2020-36235)
WordPress Plugin Gallery for Social Photo Unspecified Vulnerability (1.0.0.25)