VDB
Sign up
—

PYSEC-2015-13

Quick fix

PYSEC-2015-13 — kallithea: upgrade to the fixed version with the command below.

pip install --upgrade 'kallithea>=0.3'

Details

CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the came_from parameter to _admin/login.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/kallithea
Introduced in: 0Fixed in: 0.3
Fixpip install --upgrade 'kallithea>=0.3'

References