Access Control Bypass Affecting safeurl-python package, versions [,1.3)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-SAFEURLPYTHON-5747815
- published 30 Jun 2023
- disclosed 29 Jun 2023
- credit Sim4n6
How to fix?
Upgrade safeurl-python
to version 1.3 or higher.
Overview
safeurl-python is a library that aids developers in protecting against SSRF
Affected versions of this package are vulnerable to Access Control Bypass due to not blocking FQDNs. If a hostname is blacklisted, it is possible to bypass the blacklist by requesting the FQDN of the host (e.g. adding .
to the end).
References
CVSS Scores
version 3.1