AZL-31167
Dashboard / Vulnerabilities / AZL-31167
Summary: CVE-2023-27043 affecting package python3 for versions less than 3.9.19-9
Details: The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-27043
Affected packages
Package
Name: python3
Purl: pkg:rpm/azure-linux/python3
Affected ranges
Type: ECOSYSTEM
Events:
