VDB
BDU%3A2025-12374
BDU%3A2025-12374
PUBLISHED
CVSS 2.5999999046325684 LOW
Уязвимость функций urllib.parse.urlsplit() и urlparse() интерпретатора языка программирования Python, позволяющая нарушителю оказать воздействие на целостность данных
Risk Scores
CVSS 2.0
2.5999999046325684
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ООО «Ред Софт», ООО «РусБИТех-Астра», Python Software Foundation, АО "НППКТ", ООО «НЦПР» | РЕД ОС (запись в едином реестре российских программ №3751), Astra Linux Special Edition (запись в едином реестре российских программ №369), Python, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), МСВСфера |
Timeline
- Sep 29, 2025 CVE Published
- Feb 16, 2026 CVE Updated
References
- https://github.com/python/cpython/commit/29f348e232e82938ba2165843c448c2b291504c5 url
- https://github.com/python/cpython/commit/ddca2953191c67a12b1f19d6bca41016c6ae7132 url
- https://github.com/python/cpython/pull/103849 url
- https://wiki.astralinux.ru/astra-linux-se18-bulletin-2025-0811SE18 url
- http://repo.red-soft.ru/redos/8.0/x86_64/updates/ url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-1020SE47 advisory
- https://errata.msvsphere-os.ru/definition/9/INFCSA-2024:10983?lang=ru advisory
- https://github.com/python/cpython/commit/634ded45545ce8cbd6fd5d49785613dd7fa9b89e url
- https://github.com/python/cpython/commit/b2171a2fd41416cf68afd67460578631d755a550 url
- https://nvd.nist.gov/vuln/detail/CVE-2024-11168 url
- https://security.netapp.com/advisory/ntap-20250411-0004/ url
- https://security-tracker.debian.org/tracker/CVE-2024-11168 url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2025-0923SE17 url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.13/ url
- https://github.com/python/cpython/issues/103848 advisory
- https://wiki.astralinux.ru/astra-linux-se38-bulletin-2026-0126SE38 advisory