GHSA-xpwp-rq3x-x6v7
Dashboard / Vulnerabilities / GHSA-xpwp-rq3x-x6v7
Summary: Critical severity vulnerability that affects recurly-api-client
Details: The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery vulnerability due to incorrect use of "Uri.EscapeUriString" that could result in compromise of API keys or other critical resources.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-0907, https://github.com/recurly/recurly-client-net/commit/9eef460c0084afd5c24d66220c8b7a381cf9a1f1, https://hackerone.com/reports/288635, https://dev.recurly.com/page/net-updates, https://github.com/advisories/GHSA-xpwp-rq3x-x6v7
Affected packages
Package
Name: recurly-api-client
Purl: pkg:nuget/recurly-api-client
Affected ranges
Type: ECOSYSTEM
Events:
