[issue36276] Python urllib CRLF injection vulnerability

2019-03-14 Thread ragdoll
ragdoll added the comment: OK -- ___ Python tracker <https://bugs.python.org/issue36276> ___ ___ Python-bugs-list mailing list Unsubscribe: https://mail.pyth

[issue36276] Python urllib CRLF injection vulnerability

2019-03-12 Thread ragdoll
New submission from ragdoll : Abstract: A CRLF injection vulnerability of Python built-in urllib module (“urllib2” in 2.x,”urllib” in 3.x) was found by our team. Attacker who has the control of the requesting address parameter, could exploit this vulnerability to manipulate a HTTP header and