GHSA-373w-rj84-pv6x

    Dashboard / Vulnerabilities / GHSA-373w-rj84-pv6x

    GHSA-373w-rj84-pv6x

    Published: 29 Jun 2023Last Modified: 14 Feb 2025

    Summary: SafeURL-Python's hostname blocklist does not block FQDNs

    Details: ### Description If a hostname was blacklisted, it was possible to bypass the blacklist by requesting the FQDN of the host (e.g. adding `.` to the end). ### Impact The main purpose of this library is to block requests to internal/private IPs and these cannot be bypassed using this finding. But if a library user had specifically set certain hostnames as blocked, then an attacker would be able to circumvent that block to cause SSRFs to request those hostnames. ### Patches Fixed by https://github.com/IncludeSecurity/safeurl-python/pull/6 ### Credit https://github.com/Sim4n6

    Affected packages

    Package

    Name: safeurl-python

    Purl: pkg:pypi/safeurl-python

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.3

    Affected versions

    1.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-373w-rj84-pv6x | CVE-DB