CVE-2019-9636 - CVE House
Back to Database
Status published Critical CVE-2019-9636

Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected...

Vulnerability Description

Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a given hostname). The components are: urllib.parse.urlsplit, urllib.parse.urlparse. The attack vector is: A specially crafted URL could be incorrectly parsed to locate cookies or authentication data and send that information to a different host than when parsed correctly. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.7, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.3, v3.7.3rc1, v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-9636

Credits & Attribution

No credits recorded in the NVD database.

References

Affected Vendor

Affected Software

python, fedora, leap, debian linux, ubuntu linux, openshift container platform, enterprise linux, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation, virtualization, sun zfs storage appliance kit
Vulnerable Versions:
2.7.0, 3.0.0, 3.5.0, 3.6.0, 3.7.0, 28, 29, 30, 31, 15.0, 15.1, 42.3, 8.0, 9.0, 12.04, 14.04, 16.04, 18.04, 19.04, 3.11, 7.5, 6.0, 8.1, 8.2, 8.4, 8.6, 7.4, 5.6, 4.0, 8.8.6

Timeline

Official Publish: March 8th, 2019
Last Modified: August 4th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.