Executive brief
isInList in the safeurl-python package before 1.2 for Python has an insufficiently restrictive regular expression for external domains, leading to SSRF.
Affected products
- PyPI safeurl-python
Junglewise Threat Intelligence
CVE-2023-24622 · Severity: low · CVSS 3.1 · Published 2023-01-30
Technologies: safeurl-python (PyPI). Vendors: PyPI.
isInList in the safeurl-python package before 1.2 for Python has an insufficiently restrictive regular expression for external domains, leading to SSRF.