Updated python-urllib3 packages fix security vulnerability
Publication date: 25 Jan 2021Modification date: 25 Jan 2021
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-26137
Description
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest() (CVE-2020-26137).
References
SRPMS
7/core
- python-urllib3-1.24.3-1.2.mga7