An issue in the urllib.parse component of Python before v3.11 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
References
Link | Resource |
---|---|
https://pointernull.com/security/python-url-parse-problem.html | Exploit Mitigation Technical Description Third Party Advisory |
https://github.com/python/cpython/pull/99421 | Patch |
Configurations
Information
Published : 2023-02-17 07:15
Updated : 2023-02-27 11:28
NVD link : CVE-2023-24329
Mitre link : CVE-2023-24329
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
python
- python