Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qxg5-mcmp-m3m9

Опубликовано: 13 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 6.3
CVSS3: 3.7

Описание

The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts ([]), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser.

The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts ([]), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser.

EPSS

Процентиль: 42%
0.00198
Низкий

6.3 Medium

CVSS4

3.7 Low

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 3.7
ubuntu
7 месяцев назад

The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser.

CVSS3: 3.7
redhat
7 месяцев назад

The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser.

CVSS3: 3.7
nvd
7 месяцев назад

The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser.

CVSS3: 3.7
msrc
7 месяцев назад

Описание отсутствует

CVSS3: 3.7
debian
7 месяцев назад

The urllib.parse.urlsplit() and urlparse() functions improperly valida ...

EPSS

Процентиль: 42%
0.00198
Низкий

6.3 Medium

CVSS4

3.7 Low

CVSS3

Дефекты

CWE-918