VDB
Sign up
LOW

GHSA-373w-rj84-pv6x

SafeURL-Python's hostname blocklist does not block FQDNs

Quick fix

GHSA-373w-rj84-pv6x — safeurl-python: upgrade to the fixed version with the command below.

pip install --upgrade 'safeurl-python>=1.3'

Details

### Description If a hostname was blacklisted, it was possible to bypass the blacklist by requesting the FQDN of the host (e.g. adding `.` to the end).

### Impact The main purpose of this library is to block requests to internal/private IPs and these cannot be bypassed using this finding. But if a library user had specifically set certain hostnames as blocked, then an attacker would be able to circumvent that block to cause SSRFs to request those hostnames.

### Patches Fixed by https://github.com/IncludeSecurity/safeurl-python/pull/6

### Credit https://github.com/Sim4n6

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/safeurl-python
Introduced in: 0Fixed in: 1.3
Fixpip install --upgrade 'safeurl-python>=1.3'

References