CVE-2024-11168
EUVD-2024-3431912.11.2024, 22:15
The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| python_software_foundation | cpython | 𝑥 < 3.11.4 | ADP |
| python_software_foundation | cpython | 3.12.0a1 ≤ 𝑥 < 3.12.0b1 | ADP |
Debian Releases
Debian Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| pypy3 |
| ||||||||||||
| python3.11 |
| ||||||||||||
| python3.9 |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| python2.7 |
| ||||||||||||||||||
| python3.4 |
| ||||||||||||||||||
| python3.5 |
| ||||||||||||||||||
| python3.6 |
| ||||||||||||||||||
| python3.7 |
| ||||||||||||||||||
| python3.8 |
| ||||||||||||||||||
| python3.9 |
| ||||||||||||||||||
| python3.10 |
| ||||||||||||||||||
| python3.11 |
| ||||||||||||||||||
| python3.12 |
| ||||||||||||||||||
| python3.13 |
|
References