github.com
https://github.com/pypa/advisory-database/tree/main/vulns/pypiserver/PYSEC-2019-113.yaml CVE-2019-6802
MEDIUMNuclei
CRLF Injection in pypiserver
Record summary
CVE-2019-6802 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
pypiserverBrowse PyPI / pypiserver | GitHub Advisory | Before 1.2.6 · Fixed in 1.2.6 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMPypiserver <1.2.5 - Carriage Return Line Feed InjectionCVSS 6.1
Pypiserver through 1.2.5 and below is susceptible to carriage return line feed injection. An attacker can set arbitrary HTTP headers and possibly conduct cross-site scripting attacks via a %0d%0a in a URI.
Impact
Attackers can inject arbitrary HTTP headers through CRLF injection, potentially conducting cross-site scripting attacks or cache poisoning.
Remediation
Upgrade to Pypiserver version 1.2.5 or later.
WeaknessesCWE-74
Authors0x_Akoko
Template tagscvecve2019crlfpypiserverpythonvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:python:pypiserver:*:*:*:*:*:*:*:*
Shodan: html:"pypiserver"
Shodan: http.html:"pypiserver"
FOFA: body="pypiserver"
https://vuldb.com/?id.130257 https://github.com/pypiserver/pypiserver/issues/237 https://nvd.nist.gov/vuln/detail/CVE-2019-6802 https://github.com/ARPSyndicate/cvemon https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
5github.com
https://github.com/pypiserver/pypiserver github.com
https://github.com/pypiserver/pypiserver/commit/1375a67c55a9b8d4619df30d2a1c0b239d7357e6 github.com
https://github.com/pypiserver/pypiserver/issues/237 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-6802