Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-24329

Опубликовано: 17 фев. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.

A flaw was found in the Python package. An issue in the urllib.parse component could allow attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.This may lead to compromised Integrity.

Отчет

Versions of python36:3.6/python36 as shipped with Red Hat Enterprise Linux 8 are marked as 'Not affected' as they just provide "symlinks" to the main python3 component, which provides the actual interpreter of the Python programming language.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8gimp:flatpak/python2Affected
Red Hat Enterprise Linux 8inkscape:flatpak/python2Affected
Red Hat Enterprise Linux 8python36:3.6/python36Not affected
Red Hat Enterprise Linux 6 Extended Lifecycle SupportpythonFixedRHSA-2023:355008.06.2023
Red Hat Enterprise Linux 7pythonFixedRHSA-2023:355509.06.2023
Red Hat Enterprise Linux 7python3FixedRHSA-2023:355609.06.2023
Red Hat Enterprise Linux 8python3FixedRHSA-2023:359114.06.2023
Red Hat Enterprise Linux 8python3.11FixedRHSA-2023:359414.06.2023
Red Hat Enterprise Linux 8python27FixedRHSA-2023:378022.06.2023
Red Hat Enterprise Linux 8python38FixedRHSA-2023:378122.06.2023

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2173917python: urllib.parse url blocklisting bypass

EPSS

Процентиль: 77%
0.0105
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.

CVSS3: 7.5
nvd
больше 2 лет назад

An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.

CVSS3: 7.5
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 2 лет назад

An issue in the urllib.parse component of Python before 3.11.4 allows ...

suse-cvrf
почти 2 года назад

Security update for python

EPSS

Процентиль: 77%
0.0105
Низкий

7.5 High

CVSS3