Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xjjg-vmw6-c2p9

Опубликовано: 27 авг. 2019
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

Open Redirect in httpie

All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a request from HTTP to a crafted URL pointing to a server in his or hers control.

Пакеты

Наименование

httpie

pip
Затронутые версииВерсия исправления

< 1.0.3

1.0.3

EPSS

Процентиль: 79%
0.02045
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 7 лет назад

All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a request from HTTP to a crafted URL pointing to a server in his or hers control.

CVSS3: 8.8
nvd
почти 7 лет назад

All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a request from HTTP to a crafted URL pointing to a server in his or hers control.

CVSS3: 8.8
debian
почти 7 лет назад

All versions of the HTTPie package prior to version 1.0.3 are vulnerab ...

suse-cvrf
почти 7 лет назад

Security update for httpie

EPSS

Процентиль: 79%
0.02045
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-601