CVE Database
/

CVE-2021-23336

Back to search

CVE-2021-23336

Published: Feb 15, 2021

Modified: Dec 17, 2025

PUBLISHED

CVSS v3.1

5.9

MEDIUM

Description

The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configuration) and the server. This can result in malicious requests being cached as completely safe ones, as the proxy would usually not see the semicolon as a separator, and therefore would not include it in a cache key of an unkeyed parameter.

VendorProductVersions

n/a

python/cpython

affected
0 - < unspecified
affected
unspecified - < 3.6.13
affected
3.7.0 - < unspecified
affected
unspecified - < 3.7.10
affected
3.8.0 - < unspecified

+3 more versions

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H/E:P/RL:U/RC:C

Attack Vector

Network

Attack Complexity

High

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

None

Integrity

Low

Availability

High

References

FEDORA-2021-7547ad987f
vendor-advisory
FEDORA-2021-f4fd9372c7
vendor-advisory
FEDORA-2021-3352c1c802
vendor-advisory
FEDORA-2021-7d3a9004e2
vendor-advisory
FEDORA-2021-907f3bacae
vendor-advisory
FEDORA-2021-7c1bb32d13
vendor-advisory
FEDORA-2021-b1843407ca
vendor-advisory
FEDORA-2021-2897f5366c
vendor-advisory
FEDORA-2021-b326fcb83f
vendor-advisory
FEDORA-2021-1bb399a5af
vendor-advisory
FEDORA-2021-ef83e8525a
vendor-advisory
FEDORA-2021-b76ede8f4d
vendor-advisory
FEDORA-2021-309bc2e727
vendor-advisory
FEDORA-2021-5a09621ebb
vendor-advisory
FEDORA-2021-e22bb0e548
vendor-advisory
FEDORA-2021-e525e48886
vendor-advisory
FEDORA-2021-b6b6093b3a
vendor-advisory
GLSA-202104-04
vendor-advisory
FEDORA-2021-98720f3785
vendor-advisory
FEDORA-2021-12df7f7382
vendor-advisory

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now