You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Backport CVE-2023-24329 to all in-service releases: urlparse does not correctly handle schemes that begin with ASCII digits, '+', '-', and '.' characters
#102293
Closed
RSAlderman opened this issue
Feb 27, 2023
· 1 comment
Backport CVE-2023-24329 (CVSS 7.5: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N) to all in-service releases: urlparse does not correctly handle schemes that begin with ASCII digits, '+', '-', and '.' characters which was backported to 3.11.1 only
Feature or enhancement
Backport CVE-2023-24329 (CVSS 7.5: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N) to all in-service releases: urlparse does not correctly handle schemes that begin with ASCII digits, '+', '-', and '.' characters which was backported to 3.11.1 only
Pitch
This is a security vulnerability that has only been backported to 3.11.1, not the other releases (3.7-3.10) that are currently supported.
Previous discussion
Is it possible to get an idea of a timescale for such as backport to be implemented in the earlier supported releases?
The text was updated successfully, but these errors were encountered: