Safety vulnerability ID: 72631
The information on this page was manually curated by our Cybersecurity Intelligence Team.
[This advisory has been limited. Please create a free account to view the full advisory.]
Latest version: 1.8.9
WSGI request and response object
[This affected versions has been limited. Please create a free account to view the full affected versions.]
[This fixed versions has been limited. Please create a free account to view the full fixed versions.]
---
First release. Nothing is new, or everything is new, depending on how
you think about it.
Unreleased
----------
Security Fix
~~~~~~~~~~~~
- The use of WebOb's Response object to redirect a request to a new location
can lead to an open redirect if the Location header is not a full URI.
See https://github.com/Pylons/webob/security/advisories/GHSA-mg3v-6m49-jhp3
and CVE-2024-42353
Thanks to Sara Gao for the report
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application