Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-24329
HistoryFeb 17, 2023 - 12:00 a.m.

CVE-2023-24329

2023-02-1700:00:00
ubuntu.com
ubuntu.com
41
python
urllib
parse
vulnerability
cve-2023-24329
bypassing
blocklisting
discussions
effectiveness

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

41.7%

An issue in the urllib.parse component of Python before 3.11.4 allows
attackers to bypass blocklisting methods by supplying a URL that starts
with blank characters.

Bugs

Notes

Author Note
leosilva there are some discussions around that issue that raises doubts about if it was properly fixed or not. till further investigation it’ll be marked as needed again.

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

41.7%