[issue38576] CVE-2019-18348: CRLF injection via the host part of the url passed to urlopen()

Gregory P. Smith report at bugs.python.org
Sat Mar 14 20:59:13 EDT 2020


Gregory P. Smith <greg at krypto.org> added the comment:

If anyone cares about 2.7, the *final* release is coming up in a few weeks.  They'll need to figure out what it looks like there and get a 2.7 PR reviewed by the release manager.

----------
resolution:  -> fixed
stage: patch review -> resolved
status: open -> closed
versions:  -Python 3.6, Python 3.7, Python 3.8, Python 3.9

_______________________________________
Python tracker <report at bugs.python.org>
<https://bugs.python.org/issue38576>
_______________________________________


More information about the Python-bugs-list mailing list