Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Backport CVE-2023-24329 to all in-service releases: urlparse does not correctly handle schemes that begin with ASCII digits, '+', '-', and '.' characters #102293

Closed
RSAlderman opened this issue Feb 27, 2023 · 1 comment
Labels
type-feature A feature request or enhancement type-security A security issue

Comments

@RSAlderman
Copy link

Feature or enhancement

Backport CVE-2023-24329 (CVSS 7.5: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N) to all in-service releases: urlparse does not correctly handle schemes that begin with ASCII digits, '+', '-', and '.' characters which was backported to 3.11.1 only

Pitch

This is a security vulnerability that has only been backported to 3.11.1, not the other releases (3.7-3.10) that are currently supported.

Previous discussion

Is it possible to get an idea of a timescale for such as backport to be implemented in the earlier supported releases?

@RSAlderman RSAlderman added the type-feature A feature request or enhancement label Feb 27, 2023
@AlexWaygood AlexWaygood added the type-security A security issue label Feb 27, 2023
@gpshead
Copy link
Member

gpshead commented Feb 27, 2023

I'm closing this as a duplicate of #102153 as it isn't clear that all of this was even fixed. We'll make any decision on what to backport it to there.

@gpshead gpshead closed this as completed Feb 27, 2023
@gpshead gpshead closed this as not planned Won't fix, can't repro, duplicate, stale Apr 27, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
type-feature A feature request or enhancement type-security A security issue
Projects
None yet
Development

No branches or pull requests

3 participants