Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-11168

Опубликовано: 12 нояб. 2024
Источник: debian
EPSS Низкий

Описание

The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.12not-affectedpackage
python3.11fixed3.11.4-1package
python3.11fixed3.11.2-6+deb12u5bookwormpackage
python3.9removedpackage
pypy3fixed7.3.18+dfsg-1package
pypy3postponedbullseyepackage

Примечания

  • https://github.com/python/cpython/issues/103848

  • https://github.com/python/cpython/pull/103849

  • https://github.com/python/cpython/commit/29f348e232e82938ba2165843c448c2b291504c5 (v3.12.0b1)

  • https://github.com/python/cpython/commit/b2171a2fd41416cf68afd67460578631d755a550 (v3.11.4)

EPSS

Процентиль: 48%
0.0025
Низкий

Связанные уязвимости

CVSS3: 3.7
ubuntu
9 месяцев назад

The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser.

CVSS3: 3.7
redhat
9 месяцев назад

The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser.

CVSS3: 3.7
nvd
9 месяцев назад

The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser.

CVSS3: 3.7
msrc
8 месяцев назад

Описание отсутствует

suse-cvrf
4 месяца назад

Security update for python3

EPSS

Процентиль: 48%
0.0025
Низкий