Overview
Request 700429 superseded
- bsc#1130840 (CVE-2019-9947): add CVE-2019-9947-no-ctrl-char-http.patch
Address the issue by disallowing URL paths with embedded
whitespace or control characters through into the underlying
http client request. Such potentially malicious header
injection URLs now cause a ValueError to be raised. (forwarded request 700428 from mcepl)
- Created by mcepl
- In state superseded
- Superseded by 706252
- Open review for openSUSE:Factory:Staging:A
Request History
mcepl created request
- bsc#1130840 (CVE-2019-9947): add CVE-2019-9947-no-ctrl-char-http.patch
Address the issue by disallowing URL paths with embedded
whitespace or control characters through into the underlying
http client request. Such potentially malicious header
injection URLs now cause a ValueError to be raised. (forwarded request 700428 from mcepl)
factory-auto added opensuse-review-team as a reviewer
Please review sources
licensedigger accepted review
ok
factory-auto accepted review
Check script succeeded
namtrac accepted review
staging-bot set openSUSE:Factory:Staging:B as a staging project
Being evaluated by staging project "openSUSE:Factory:Staging:B"
staging-bot accepted review
Picked openSUSE:Factory:Staging:B
dimstar_suse accepted review
Removing from openSUSE:Factory:Staging:B, re-evaluation needed
dimstar_suse approved review
Removing from openSUSE:Factory:Staging:B, re-evaluation needed
dimstar_suse added factory-staging as a reviewer
Requesting new staging review
dimstar_suse set openSUSE:Factory:Staging:M as a staging project
Being evaluated by staging project "openSUSE:Factory:Staging:M"
dimstar_suse accepted review
Picked openSUSE:Factory:Staging:M
dimstar_suse set openSUSE:Factory:Staging:C as a staging project
Being evaluated by staging project "openSUSE:Factory:Staging:C"
dimstar accepted review
Being evaluated in :C
dimstar_suse accepted review
Removing from openSUSE:Factory:Staging:C, re-evaluation needed
dimstar_suse approved review
Removing from openSUSE:Factory:Staging:C, re-evaluation needed
dimstar_suse added factory-staging as a reviewer
Requesting new staging review
dimstar_suse set openSUSE:Factory:Staging:C as a staging project
Being evaluated by staging project "openSUSE:Factory:Staging:C"
dimstar_suse accepted review
Picked openSUSE:Factory:Staging:C
dimstar_suse accepted review
Removing from openSUSE:Factory:Staging:C, re-evaluation needed
dimstar_suse approved review
Removing from openSUSE:Factory:Staging:C, re-evaluation needed
dimstar_suse added factory-staging as a reviewer
Requesting new staging review
dimstar_suse set openSUSE:Factory:Staging:A as a staging project
Being evaluated by staging project "openSUSE:Factory:Staging:A"
dimstar_suse accepted review
Picked openSUSE:Factory:Staging:A
dimstar_suse superseded request
superseded by 706252
Break urllib3:test
https://bugzilla.opensuse.org/show_bug.cgi?id=1136184