ZeroHour

CVE-2023-24329

PoC 1
CVSS 3.1
7.5 high
EPSS
20%p97
Published
()
Modified
Description

An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.

Vendors
pythonfedoraprojectnetapp
Products
python, fedora, active iq unified manager, management services for element software, management services for netapp hci, ontap select deploy administration utility
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news