CVE Database
/

CVE-2018-20852

Back to search

CVE-2018-20852

Published: Jul 13, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server. An attacker may abuse this flaw by using a server with a hostname that has another valid hostname as a suffix (e.g., pythonicexample.com to steal cookies for example.com). When a program uses http.cookiejar.DefaultPolicy and tries to do an HTTP connection to an attacker-controlled server, existing cookies can be leaked to the attacker. This affects 2.x through 2.7.16, 3.x before 3.4.10, 3.5.x before 3.5.7, 3.6.x before 3.6.9, and 3.7.x before 3.7.3.

VendorProductVersions

n/a

n/a

affected
n/a

References

openSUSE-SU-2019:1988
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:1989
vendor-advisory
x_refsource_SUSE
USN-4127-2
vendor-advisory
x_refsource_UBUNTU
USN-4127-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2019:3725
vendor-advisory
x_refsource_REDHAT
FEDORA-2019-0d3fcae639
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-74ba24605e
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-758824a3ff
vendor-advisory
x_refsource_FEDORA
RHSA-2019:3948
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2020:0086
vendor-advisory
x_refsource_SUSE
GLSA-202003-26
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now