CVE-2019-9948

CRITICAL

Python <2.7.17 - SSRF

Title source: llm

Description

urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call.

References (22)

... and 2 more

Scores

CVSS v3 9.1
EPSS 0.0092
EPSS Percentile 75.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Classification

CWE
CWE-22
Status published

Affected Products (26)

python/python < 2.7.17
opensuse/leap
opensuse/leap
debian/debian_linux
debian/debian_linux
fedoraproject/fedora
fedoraproject/fedora
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
redhat/enterprise_linux_desktop
redhat/enterprise_linux_desktop
redhat/enterprise_linux_eus
... and 11 more

Timeline

Published Mar 23, 2019
Tracked Since Feb 18, 2026