Overview

Request 893784 accepted

Note: This request syncs the urllib3 package with the released state we have in
SUSE OpenStack Cloud 9 right now.

- Add CVE-2020-26116-CRLF-injection.patch which raises ValueError
if method contains control characters and thus prevents CRLF
injection into URLs (bsc#1177211, bpo#39603, CVE-2020-26116,
gh#urllib3/urllib3#1800).

Request History
Johannes Grassler's avatar

jgrassler created request

Note: This request syncs the urllib3 package with the released state we have in
SUSE OpenStack Cloud 9 right now.

- Add CVE-2020-26116-CRLF-injection.patch which raises ValueError
if method contains control characters and thus prevents CRLF
injection into URLs (bsc#1177211, bpo#39603, CVE-2020-26116,
gh#urllib3/urllib3#1800).


Gayane Osipyan's avatar

gosipyan accepted request

openSUSE Build Service is sponsored by