Lucene search

K
cloudlinuxCloudLinuxCLSA-2023:1689886440
HistoryJul 20, 2023 - 8:54 p.m.

python: Fix of CVE-2023-24329

2023-07-2020:54:04
repo.cloudlinux.com
20
python
cve-2023-24329
urlsplit
control characters
non-ascii
unix

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

41.6%

  • CVE-2023-24329: part2: Start stripping C0 control and space chars in urlsplit
  • Also correct the first CVE-2023-24329 patch: Fix test_attributes_bad_scheme
    to check for non-ascii symbol as first character of url

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

41.6%