Description
isInList in the safeurl-python package before 1.2 for Python has an insufficiently restrictive regular expression for external domains, leading to SSRF.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0298 | isInList in the safeurl-python package before 1.2 for Python has an insufficiently restrictive regular expression for external domains, leading to SSRF. |
Github GHSA |
GHSA-jgh8-vchw-q3g7 | safeurl-python contains Server-Side Request Forgery |
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 28 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-28T14:27:49.215Z
Reserved: 2023-01-30T00:00:00.000Z
Link: CVE-2023-24622
Updated: 2024-08-02T11:03:19.044Z
Status : Modified
Published: 2023-01-30T05:15:10.307
Modified: 2025-03-28T15:15:43.787
Link: CVE-2023-24622
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA