Insecure functionality In pypy3
Description
An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 14 | 7.3.12+dfsg-1 | ||
debian 12 | 7.3.11+dfsg-2+deb12u2 | ||
debian 13 | 7.3.12+dfsg-1 | ||
debian 12 | 3.11.2-6+deb12u2 | ||
rpm rhel8 | 0:3.9.16-1.module+el8.8.0+18968+3d7b19f0.1 | ||
rpm rhel9.0 | 0:3.9.10-4.el9_0.1 | ||
rpm rhel8 | 0:3.8.16-1.module+el8.8.0+18967+20d359ae.1 | ||
rpm rhel8.6 | 0:3.8.12-1.module+el8.6.0+19204+eee15c0a.2 | ||
rpm rhel7 | 0:3.6.8-19.el7_9 | ||
rpm rhel8.6 | 0:3.6.8-47.el8_6.1 |
1-10 of 22
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17. 18. 19. 20. 21. 22. 23. 24. 25. 26. 27. 28. 29. 30. 31. 32. 33.
References
1. 2. 3. 4.