GHSA-373w-rj84-pv6x
SafeURL-Python's hostname blocklist does not block FQDNs
Quick fix
GHSA-373w-rj84-pv6x — safeurl-python: upgrade to the fixed version with the command below.
pip install --upgrade 'safeurl-python>=1.3'Details
### Description If a hostname was blacklisted, it was possible to bypass the blacklist by requesting the FQDN of the host (e.g. adding `.` to the end).
### Impact The main purpose of this library is to block requests to internal/private IPs and these cannot be bypassed using this finding. But if a library user had specifically set certain hostnames as blocked, then an attacker would be able to circumvent that block to cause SSRFs to request those hostnames.
### Patches Fixed by https://github.com/IncludeSecurity/safeurl-python/pull/6
### Credit https://github.com/Sim4n6
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/IncludeSecurity/safeurl-python/security/advisories/GHSA-373w-rj84-pv6x[WEB]
- https://github.com/IncludeSecurity/safeurl-python/pull/6[WEB]
- https://github.com/IncludeSecurity/safeurl-python/commit/c4f9677f8790a58eaa1953bac286cca75a5f580e[WEB]
- https://github.com/IncludeSecurity/safeurl-python[PACKAGE]