| CNNVD-ID编号 | CNNVD-201904-910 | CVE编号 | CVE-2019-11324 |
| 发布时间 | 2019-04-18 | 更新时间 | 2021-02-04 |
| 漏洞类型 | 信任管理问题 | 漏洞来源 | N/A |
| 危险等级 | 高危 | 威胁类型 | 远程 |
| 厂商 | N/A | ||
urllib3是一款Python HTTP库。该产品具有线程安全连接池、文件发布支持等。
urllib3 1.24.2之前版本中存在信任管理问题漏洞。该漏洞源于网络系统或产品中缺乏有效的信任管理机制。攻击者可利用默认密码或者硬编码密码、硬编码证书等攻击受影响组件。
目前厂商已发布新版本,以修复此安全问题,详情请关注厂商主页:
https://github.com/urllib3/urllib3/
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00041.html
来源:UBUNTU
来源:MLIST
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00039.html
来源:MISC
链接:https://github.com/urllib3/urllib3/compare/a6ec68a...1efadf4
来源:usn.ubuntu.com
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192267-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192300-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192332-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192331-1.html
来源:access.redhat.com
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192370-1.html
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:nvd.nist.gov
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/157669/Red-Hat-Security-Advisory-2020-2068-01.html
来源:www.auscert.org.au
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/158637/Red-Hat-Security-Advisory-2020-3194-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/152979/Ubuntu-Security-Notice-USN-3990-1.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/156791/Red-Hat-Security-Advisory-2020-0850-01.html
来源:www.ibm.com
来源:www.ibm.com
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/157446/Red-Hat-Security-Advisory-2020-1605-01.html
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/159727/Red-Hat-Security-Advisory-2020-4298-01.html
暂无