CVE & CISA-KEV Catalog

CVE-2019-10160

CRITICALEPSS 91th pctl
9.8
CVSS v3
NVD

Description

A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application.

How to fix

Remediation Available
python2.7Debian
Fixed in:2.7.16-3CVE-2019-10160
python2.7Ubuntu
Fixed in:2.7.6-8ubuntu0.6+esm2USN-4127-2
Fixed in:2.7.12-1ubuntu0~16.04.8USN-4127-1
Fixed in:2.7.15-4ubuntu4~18.04.1USN-4127-1
python2.7-minimalUbuntu
Fixed in:2.7.6-8ubuntu0.6+esm2USN-4127-2
Fixed in:2.7.12-1ubuntu0~16.04.8USN-4127-1
Fixed in:2.7.15-4ubuntu4~18.04.1USN-4127-1
python3.10Ubuntu
Fixed in:3.10.12-1~22.04.4USN-6891-1
python3.10-minimalUbuntu
Fixed in:3.10.12-1~22.04.4USN-6891-1
python3.11Ubuntu
Fixed in:3.11.0~rc1-1~22.04.1~esm1USN-6891-1
Fixed in:3.11.6-3ubuntu0.1USN-6891-1
python3.11-minimalUbuntu
Fixed in:3.11.0~rc1-1~22.04.1~esm1USN-6891-1
Fixed in:3.11.6-3ubuntu0.1USN-6891-1
python3.12Ubuntu
Fixed in:3.12.0-1ubuntu0.1USN-6891-1
python3.12-minimalUbuntu
Fixed in:3.12.0-1ubuntu0.1USN-6891-1
python3.4Ubuntu
Fixed in:3.4.3-1ubuntu1~14.04.7+esm2USN-4127-2
python3.4-minimalUbuntu
Fixed in:3.4.3-1ubuntu1~14.04.7+esm2USN-4127-2
python3.5Ubuntu
Fixed in:3.5.2-2ubuntu0~16.04.4~14.04.1+esm1USN-6891-1
Fixed in:3.5.2-2ubuntu0~16.04.13+esm13USN-6891-1
Fixed in:3.5.2-2ubuntu0~16.04.8USN-4127-1
python3.5-minimalUbuntu
Fixed in:3.5.2-2ubuntu0~16.04.4~14.04.1+esm1USN-6891-1
Fixed in:3.5.2-2ubuntu0~16.04.13+esm13USN-6891-1
Fixed in:3.5.2-2ubuntu0~16.04.8USN-4127-1
python3.6Ubuntu
Fixed in:3.6.8-1~18.04.2USN-4127-1
Fixed in:3.6.9-1~18.04ubuntu1.13+esm2USN-6891-1
python3.6-minimalUbuntu
Fixed in:3.6.8-1~18.04.2USN-4127-1
Fixed in:3.6.9-1~18.04ubuntu1.13+esm2USN-6891-1
python3.7Ubuntu
Fixed in:3.7.5-2ubuntu1~18.04.2+esm3USN-6891-1
python3.7-minimalUbuntu
Fixed in:3.7.5-2ubuntu1~18.04.2+esm3USN-6891-1
python3.8Ubuntu
Fixed in:3.8.0-3ubuntu1~18.04.2+esm2USN-6891-1
Fixed in:3.8.10-0ubuntu1~20.04.10USN-6891-1
python3.8-minimalUbuntu
Fixed in:3.8.0-3ubuntu1~18.04.2+esm2USN-6891-1
Fixed in:3.8.10-0ubuntu1~20.04.10USN-6891-1
python3.9Ubuntu
Fixed in:3.9.5-3ubuntu0~20.04.1+esm2USN-6891-1
python3.9-minimalUbuntu
Fixed in:3.9.5-3ubuntu0~20.04.1+esm2USN-6891-1
Python 2Windows application
Affected:3.7.0 3.7.4Fixed in:3.7.4Python Software Foundation
Affected:3.6.0 3.6.9Fixed in:3.6.9Python Software Foundation
Affected:3.5.0 3.5.8Fixed in:3.5.8Python Software Foundation
Affected:2.7.0 2.7.17Fixed in:2.7.17Python Software Foundation
Python 3.10Windows application
Affected:3.7.0 3.7.4Fixed in:3.7.4Python Software Foundation
Affected:2.7.0 2.7.17Fixed in:2.7.17Python Software Foundation
Affected:3.5.0 3.5.8Fixed in:3.5.8Python Software Foundation
Affected:3.6.0 3.6.9Fixed in:3.6.9Python Software Foundation
Python 3.11Windows application
Affected:3.7.0 3.7.4Fixed in:3.7.4Python Software Foundation
Affected:3.5.0 3.5.8Fixed in:3.5.8Python Software Foundation
Affected:3.6.0 3.6.9Fixed in:3.6.9Python Software Foundation
Affected:2.7.0 2.7.17Fixed in:2.7.17Python Software Foundation
Python 3.12Windows application
Affected:3.7.0 3.7.4Fixed in:3.7.4Python Software Foundation
Affected:2.7.0 2.7.17Fixed in:2.7.17Python Software Foundation
Affected:3.5.0 3.5.8Fixed in:3.5.8Python Software Foundation
Affected:3.6.0 3.6.9Fixed in:3.6.9Python Software Foundation
Python 3.8Windows application
Affected:2.7.0 2.7.17Fixed in:2.7.17Python Software Foundation
Affected:3.5.0 3.5.8Fixed in:3.5.8Python Software Foundation
Affected:3.7.0 3.7.4Fixed in:3.7.4Python Software Foundation
Affected:3.6.0 3.6.9Fixed in:3.6.9Python Software Foundation
Python 3.9Windows application
Affected:2.7.0 2.7.17Fixed in:2.7.17Python Software Foundation
Affected:3.6.0 3.6.9Fixed in:3.6.9Python Software Foundation
Affected:3.7.0 3.7.4Fixed in:3.7.4Python Software Foundation
Affected:3.5.0 3.5.8Fixed in:3.5.8Python Software Foundation

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged

Impact

ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploit Intelligence

5.23%probability of exploitation in 30 days
91stpercentile

High risk: more likely to be exploited than 91% of all known CVEs.

References

Embed a live status badge for CVE-2019-10160
CVE-2019-10160 severity badge

Markdown

[![CVE-2019-10160](https://tridentstack.com/cve/badge/CVE-2019-10160.svg)](https://tridentstack.com/cve/CVE-2019-10160)

HTML

<a href="https://tridentstack.com/cve/CVE-2019-10160"><img src="https://tridentstack.com/cve/badge/CVE-2019-10160.svg" alt="CVE-2019-10160"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

Start free

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2024-11-21.