VDB
BDU%3A2022-07059
BDU%3A2022-07059
PUBLISHED
CVSS 9.399999618530273 CRITICAL
Уязвимость библиотеки Encode OSS HTTPX, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю обойти существующие ограничения безопасности
Risk Scores
CVSS 2.0
9.399999618530273
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения, ООО «Юбитех», Encode OSS | Debian GNU/Linux, UBLinux (запись в едином реестре российских программ №6874), Encode OSS HTTPX |
Timeline
- Nov 30, 2022 CVE Published
References
- https://encode.com/ url
- https://gist.github.com/lebr0nli/4edb76bbd3b5ff993cf44f2fbce5e571 url
- https://github.com/encode/httpx url
- https://github.com/encode/httpx/discussions/1831 url
- https://github.com/encode/httpx/issues/2184 url
- https://github.com/advisories/GHSA-h8pj-cxx2-jfg2 url
- https://github.com/encode/httpx/releases/tag/0.23.0 url
- https://security.ublinux.ru/AVG-41 url
- https://security-tracker.debian.org/tracker/CVE-2021-41945 url