Логотип exploitDog
bind:"BDU:2025-09791" OR bind:"CVE-2025-50181"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2025-09791" OR bind:"CVE-2025-50181"

Количество 11

Количество 11

fstec логотип

BDU:2025-09791

5 месяцев назад

Уязвимость HTTP библиотеки Urllib3 языка программирования Python, связанная с переадресацией URL на ненадежный сайт, позволяющая нарушителю перенаправлять пользователей на произвольный URL-адрес

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2025-50181

5 месяцев назад

urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2025-50181

5 месяцев назад

urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-50181

5 месяцев назад

urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2025-50181

4 месяца назад

urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-50181

5 месяцев назад

urllib3 is a user-friendly HTTP client library for Python. Prior to 2. ...

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02985-1

2 месяца назад

Security update for python-urllib3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02736-1

3 месяца назад

Security update for python-urllib3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02735-1

3 месяца назад

Security update for python-urllib3

EPSS: Низкий
redos логотип

ROS-20250724-09

4 месяца назад

Уязвимость python3-urllib3

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-pq67-6m6q-mj2v

5 месяцев назад

urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-09791

Уязвимость HTTP библиотеки Urllib3 языка программирования Python, связанная с переадресацией URL на ненадежный сайт, позволяющая нарушителю перенаправлять пользователей на произвольный URL-адрес

CVSS3: 5.3
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2025-50181

urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
redhat логотип
CVE-2025-50181

urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2025-50181

urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
msrc логотип
CVE-2025-50181

urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation

CVSS3: 5.3
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-50181

urllib3 is a user-friendly HTTP client library for Python. Prior to 2. ...

CVSS3: 5.3
0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02985-1

Security update for python-urllib3

0%
Низкий
2 месяца назад
suse-cvrf логотип
SUSE-SU-2025:02736-1

Security update for python-urllib3

0%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2025:02735-1

Security update for python-urllib3

0%
Низкий
3 месяца назад
redos логотип
ROS-20250724-09

Уязвимость python3-urllib3

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-pq67-6m6q-mj2v

urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation

CVSS3: 5.3
0%
Низкий
5 месяцев назад

Уязвимостей на страницу