CVE-2023-24329
python: urllib.parse url blocklisting bypass
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
5Exploited in Wild
-Decision
Descriptions
An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
A flaw was found in the Python package. An issue in the urllib.parse component could allow attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.This may lead to compromised Integrity.
Red Hat Single Sign-On is an integrated sign-on solution, available as a Red Hat JBoss Middleware for OpenShift containerized image. The Red Hat Single Sign-On for OpenShift image provides an authentication server that you can use to log in centrally, log out, and register. You can also manage user accounts for web applications, mobile applications, and RESTful web services. This erratum releases a new image for Red Hat Single Sign-On 7.6.4 for use within the OpenShift Container Platform 3.10, OpenShift Container Platform 3.11, and within the OpenShift Container Platform 4.12 cloud computing Platform-as-a-Service for on-premise or private cloud deployments, aligning with the standalone product release. Issues addressed include a cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-01-23 CVE Reserved
- 2023-02-17 CVE Published
- 2023-08-17 First Exploit
- 2025-03-18 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (33)
URL | Tag | Source |
---|---|---|
https://github.com/python/cpython/issues/102153 | Issue Tracking | |
https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html | Mailing List |
|
https://security.netapp.com/advisory/ntap-20230324-0004 | Third Party Advisory |
|
https://www.kb.cert.org/vuls/id/127587 | Third Party Advisory |
|
URL | Date | SRC |
---|---|---|
https://github.com/JawadPy/CVE-2023-24329-Exploit | 2023-10-13 | |
https://github.com/Pandante-Central/CVE-2023-24329-codeql-test | 2023-08-18 | |
https://github.com/H4R335HR/CVE-2023-24329-PoC | 2023-08-17 | |
https://github.com/PenTestMano/CVE-2023-24329-Exploit | 2024-05-03 | |
https://pointernull.com/security/python-url-parse-problem.html | 2025-03-18 |
URL | Date | SRC |
---|---|---|
https://github.com/python/cpython/pull/99421 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | < 3.7.17 Search vendor "Python" for product "Python" and version " < 3.7.17" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | >= 3.8.0 < 3.8.17 Search vendor "Python" for product "Python" and version " >= 3.8.0 < 3.8.17" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | >= 3.9.0 < 3.9.17 Search vendor "Python" for product "Python" and version " >= 3.9.0 < 3.9.17" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | >= 3.10.0 < 3.10.12 Search vendor "Python" for product "Python" and version " >= 3.10.0 < 3.10.12" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | >= 3.11.0 < 3.11.4 Search vendor "Python" for product "Python" and version " >= 3.11.0 < 3.11.4" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 36 Search vendor "Fedoraproject" for product "Fedora" and version "36" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 37 Search vendor "Fedoraproject" for product "Fedora" and version "37" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 38 Search vendor "Fedoraproject" for product "Fedora" and version "38" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Active Iq Unified Manager Search vendor "Netapp" for product "Active Iq Unified Manager" | - | vmware_vsphere |
Affected
| ||||||
Netapp Search vendor "Netapp" | Active Iq Unified Manager Search vendor "Netapp" for product "Active Iq Unified Manager" | - | windows |
Affected
| ||||||
Netapp Search vendor "Netapp" | Management Services For Element Software Search vendor "Netapp" for product "Management Services For Element Software" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Management Services For Netapp Hci Search vendor "Netapp" for product "Management Services For Netapp Hci" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Ontap Select Deploy Administration Utility Search vendor "Netapp" for product "Ontap Select Deploy Administration Utility" | - | - |
Affected
|