Junglewise Threat Intelligence

CVE-2023-24622: PYSEC-2023-298 - isInList in the safeurl-python package before 1.2 for Python has an insufficiently restrictive regular expression for external domains, lead

CVE-2023-24622 · Severity: low · CVSS 3.1 · Published 2023-01-30

Technologies: safeurl-python (PyPI). Vendors: PyPI.

Executive brief

isInList in the safeurl-python package before 1.2 for Python has an insufficiently restrictive regular expression for external domains, leading to SSRF.

Affected products

  • PyPI safeurl-python

Related threats