Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xjjg-vmw6-c2p9

Опубликовано: 27 авг. 2019
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

Open Redirect in httpie

All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a request from HTTP to a crafted URL pointing to a server in his or hers control.

Пакеты

Наименование

httpie

pip
Затронутые версииВерсия исправления

< 1.0.3

1.0.3

EPSS

Процентиль: 65%
0.00492
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 6 лет назад

All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a request from HTTP to a crafted URL pointing to a server in his or hers control.

CVSS3: 8.8
nvd
больше 6 лет назад

All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a request from HTTP to a crafted URL pointing to a server in his or hers control.

CVSS3: 8.8
debian
больше 6 лет назад

All versions of the HTTPie package prior to version 1.0.3 are vulnerab ...

suse-cvrf
больше 6 лет назад

Security update for httpie

EPSS

Процентиль: 65%
0.00492
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-601