Vulnerability Database
Blog
FAQ
Docs
CVE-2020-35678
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2020-35678
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-35678.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-35678
Aliases
GHSA-gwp7-vqr5-h33h
PYSEC-2020-25
Related
UBUNTU-CVE-2020-35678
openSUSE-SU-2021:0132-1
openSUSE-SU-2021:0152-1
openSUSE-SU-2021:0176-1
openSUSE-SU-2021:0180-1
openSUSE-SU-2024:11216-1
openSUSE-SU-2024:13902-1
Published
2020-12-27T00:15:12Z
Modified
2025-02-19T03:11:41.381731Z
Severity
6.1 (Medium)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS Calculator
Summary
[none]
Details
Autobahn|Python before 20.12.3 allows redirect header injection.
References
https://autobahn.readthedocs.io/en/latest/changelog.html
https://github.com/crossbario/autobahn-python/compare/v20.12.2...v20.12.3
https://github.com/crossbario/autobahn-python/pull/1439
https://pypi.org/project/autobahn/20.12.3/
https://github.com/crossbario/autobahn-python
https://security-tracker.debian.org/tracker/CVE-2020-35678
Affected packages
Debian:11
/
python-autobahn
Package
Name
python-autobahn
Purl
pkg:deb/debian/python-autobahn?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
17.10.1+dfsg1-7
Ecosystem specific
{ "urgency": "not yet assigned" }
Debian:12
/
python-autobahn
Package
Name
python-autobahn
Purl
pkg:deb/debian/python-autobahn?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
17.10.1+dfsg1-7
Ecosystem specific
{ "urgency": "not yet assigned" }
Debian:13
/
python-autobahn
Package
Name
python-autobahn
Purl
pkg:deb/debian/python-autobahn?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
17.10.1+dfsg1-7
Ecosystem specific
{ "urgency": "not yet assigned" }
Git
/
github.com/crossbario/autobahn-python
Affected ranges
Type
GIT
Repo
https://github.com/crossbario/autobahn-python
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Fixed
3960cbaa017a7a3b582b52e0d043c1d9f2bf0d1b
Affected versions
19.*
19.3.3
v0.*
v0.1
v0.10.0
v0.10.1
v0.10.2
v0.10.3
v0.10.4
v0.10.5
v0.10.5-2
v0.10.6
v0.10.7
v0.10.8
v0.10.9
v0.11.0
v0.12.0
v0.12.1
v0.13.0
v0.13.1
v0.14.0
v0.14.1
v0.15.0
v0.16.0
v0.16.1
v0.17.0
v0.17.1
v0.17.2
v0.18.0
v0.18.1
v0.18.2
v0.2
v0.3
v0.3.1
v0.3.2
v0.4.0
v0.4.1
v0.4.10
v0.4.2
v0.4.3
v0.5.0
v0.5.1
v0.5.14
v0.5.2
v0.5.4
v0.5.5
v0.5.6
v0.5.7
v0.5.8
v0.5.9
v0.6.3
v0.6.4
v0.6.5
v0.7.0
v0.7.1
v0.7.2
v0.7.3
v0.7.4
v0.8.0
v0.8.1
v0.8.10
v0.8.11
v0.8.12
v0.8.12-2
v0.8.13
v0.8.14
v0.8.15
v0.8.2
v0.8.3
v0.8.4
v0.8.5
v0.8.6
v0.8.7
v0.8.8
v0.8.9
v0.9.0
v0.9.1
v0.9.2
v0.9.3
v0.9.3-2
v0.9.3-3
v0.9.4
v0.9.4-2
v0.9.5
v0.9.6
v17.*
v17.10.1
v17.5.1
v17.6.1
v17.7.1
v17.8.1
v17.9.1
v17.9.2
v17.9.3
v18.*
v18.11.1
v18.11.2
v18.12.1
v18.3.1
v18.5.1
v18.5.2
v19.*
v19.1.1
v19.10.1
v19.11.1
v19.2.1
v19.3.1
v19.3.2
v19.5.1
v19.6.1
v19.6.2
v19.7.1
v19.8.1
v19.9.1
v19.9.2
v19.9.3
v20.*
v20.1.1
v20.1.2
v20.1.3
v20.12.1
v20.12.2
v20.2.1
v20.2.2
v20.3.1
v20.4.1
v20.4.2
v20.4.3
v20.6.1
v20.6.2
v20.7.1
CVE-2020-35678 - OSV