An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
2023-02-17T15:15:12.243
2025-03-18T17:15:41.693
Modified
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | python | python | < 3.7.17 | Yes |
Application | python | python | < 3.8.17 | Yes |
Application | python | python | < 3.9.17 | Yes |
Application | python | python | < 3.10.12 | Yes |
Application | python | python | < 3.11.4 | Yes |
Operating System | fedoraproject | fedora | 36 | Yes |
Operating System | fedoraproject | fedora | 37 | Yes |
Operating System | fedoraproject | fedora | 38 | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | management_services_for_element_software | - | Yes |
Application | netapp | management_services_for_netapp_hci | - | Yes |
Application | netapp | ontap_select_deploy_administration_utility | - | Yes |