VDB
Sign up
—

PYSEC-2017-68

Quick fix

PYSEC-2017-68 — recurly: upgrade to the fixed version with the command below.

pip install --upgrade 'recurly>=049c74699ce93cf126feff06d632ea63fba36742'

Details

The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource.get" method that could result in compromise of API keys or other critical resources.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/recurly
Introduced in: 0Fixed in: 049c74699ce93cf126feff06d632ea63fba36742
Fixpip install --upgrade 'recurly>=049c74699ce93cf126feff06d632ea63fba36742'

References