CVE-2023-24329
Summary
| CVE | CVE-2023-24329 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-17 15:15:00 UTC |
| Updated | 2023-11-07 04:08:00 UTC |
| Description | An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 36 | All | All | All |
| Operating System | Fedoraproject | Fedora | 37 | All | All | All |
| Operating System | Fedoraproject | Fedora | 38 | All | All | All |
| Application | Netapp | Active Iq Unified Manager | - | All | All | All |
| Application | Netapp | Active Iq Unified Manager | - | All | All | All |
| Application | Netapp | Management Services For Element Software | - | All | All | All |
| Application | Netapp | Management Services For Netapp Hci | - | All | All | All |
| Application | Netapp | Ontap Select Deploy Administration Utility | - | All | All | All |
| Application | Python | Python | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 37 Update: mingw-python3-3.10.10-2.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 38 Update: pypy-7.3.11-3.fc38 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 38 Update: python3.11-3.11.3-2.fc38 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 37 Update: pypy-7.3.11-2.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 37 Update: mingw-python3-3.10.10-2.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| gh-99418: Make urllib.parse.urlparse enforce that a scheme must begin with an alphabetical ASCII character. by kenballus · Pull Request #99421 · python/cpython · GitHub | MISC | github.com | |
| [SECURITY] Fedora 38 Update: python3.8-3.8.16-4.fc38 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 37 Update: pypy3.9-7.3.11-2.3.9.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 38 Update: pypy3.9-7.3.11-4.3.9.fc38 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| VU#127587 - Python Parsing Error Enabling Bypass CVE-2023-24329 | CERT-VN | www.kb.cert.org | |
| CVE-2023-24329 Python Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Python URL Parse Problem – PointerNull | MISC | pointernull.com | |
| [SECURITY] Fedora 38 Update: pypy-7.3.11-3.fc38 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 37 Update: python3.9-3.9.16-2.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 38 Update: python3.7-3.7.16-4.fc38 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 38 Update: python3.8-3.8.16-4.fc38 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 38 Update: python3.11-3.11.3-2.fc38 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 37 Update: python3.11-3.11.3-2.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 37 Update: pypy3.8-7.3.11-2.3.8.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 38 Update: python2.7-2.7.18-31.fc38 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 38 Update: python3.10-3.10.11-2.fc38 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 37 Update: pypy3.8-7.3.11-2.3.8.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 38 Update: python3.9-3.9.16-4.fc38 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 37 Update: python3.9-3.9.16-2.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 37 Update: python2.7-2.7.18-27.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 36 Update: mingw-python3-3.10.10-2.fc36 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| urllib.parse space handling CVE-2023-24329 appears unfixed · Issue #102153 · python/cpython · GitHub | CONFIRM | github.com | |
| [SECURITY] Fedora 38 Update: python3.7-3.7.16-4.fc38 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 38 Update: pypy3.9-7.3.11-4.3.9.fc38 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 37 Update: python3.8-3.8.16-2.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 37 Update: pypy-7.3.11-2.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] [DLA 3575-1] python2.7 security update | MLIST | lists.debian.org | |
| [SECURITY] Fedora 37 Update: python3.6-3.6.15-16.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 37 Update: python3.8-3.8.16-2.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 38 Update: python3.10-3.10.11-2.fc38 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 37 Update: python3.11-3.11.3-2.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 38 Update: python3.6-3.6.15-18.fc38 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 38 Update: python3.9-3.9.16-4.fc38 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 36 Update: mingw-python3-3.10.10-2.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 37 Update: python2.7-2.7.18-27.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 37 Update: python3.7-3.7.16-2.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 38 Update: python3.6-3.6.15-18.fc38 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 37 Update: python3.10-3.10.11-2.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 37 Update: pypy3.9-7.3.11-2.3.9.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 37 Update: python3.6-3.6.15-16.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 37 Update: python3.10-3.10.11-2.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 38 Update: python2.7-2.7.18-31.fc38 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 37 Update: python3.7-3.7.16-2.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160722 Oracle Enterprise Linux Security Update for python3 (ELSA-2023-3556)
- 160724 Oracle Enterprise Linux Security Update for python (ELSA-2023-3555)
- 160731 Oracle Enterprise Linux Security Update for python3.9 (ELSA-2023-3595)
- 160735 Oracle Enterprise Linux Security Update for python3.11 (ELSA-2023-3594)
- 160736 Oracle Enterprise Linux Security Update for python3 (ELSA-2023-3591)
- 160743 Oracle Enterprise Linux Security Update for python3.11 (ELSA-2023-3585)
- 160754 Oracle Enterprise Linux Security Update for python (ELSA-2023-3550)
- 160772 Oracle Enterprise Linux Security Update for python38:3.8 and python38-devel:3.8 (ELSA-2023-3781)
- 160773 Oracle Enterprise Linux Security Update for python27:2.7 (ELSA-2023-3780)
- 160786 Oracle Enterprise Linux Security Update for python39:3.9 and python39-devel:3.9 (ELSA-2023-3811)
- 199245 Ubuntu Security Notification for Python Vulnerability (USN-5960-1)
- 199392 Ubuntu Security Notification for Python Vulnerability (USN-6139-1)
- 199497 Ubuntu Security Notification for Python Vulnerabilities (USN-5888-1)
- 241688 Red Hat Update for python3 (RHSA-2023:3556)
- 241689 Red Hat Update for python (RHSA-2023:3555)
- 241699 Red Hat Update for python3.9 (RHSA-2023:3595)
- 241707 Red Hat Update for python3.11 (RHSA-2023:3594)
- 241718 Red Hat Update for python3 (RHSA-2023:3591)
- 241721 Red Hat Update for python3.11 (RHSA-2023:3585)
- 241741 Red Hat Update for python39:3.9 and python39-devel:3.9 (RHSA-2023:3776)
- 241742 Red Hat Update for python27:2.7 (RHSA-2023:3777)
- 241743 Red Hat Update for python38:3.8 and python38-devel:3.8 (RHSA-2023:3781)
- 241744 Red Hat Update for python27:2.7 (RHSA-2023:3780)
- 241748 Red Hat Update for python3 (RHSA-2023:3796)
- 241749 Red Hat Update for python27:2.7 (RHSA-2023:3810)
- 241750 Red Hat Update for python39:3.9 and python39-devel:3.9 (RHSA-2023:3811)
- 241762 Red Hat Update for python3 (RHSA-2023:3936)
- 241763 Red Hat Update for python3 (RHSA-2023:3935)
- 241764 Red Hat Update for python27:2.7 (RHSA-2023:3931)
- 241766 Red Hat Update for python27:2.7 (RHSA-2023:3932)
- 241767 Red Hat Update for python3 (RHSA-2023:3934)
- 241778 Red Hat Update for python39:3.9 and python39-devel:3.9 (RHSA-2023:4004)
- 241779 Red Hat Update for python38:3.8 and python38-devel:3.8 (RHSA-2023:4008)
- 241785 Red Hat Update for python38:3.8 and python38-devel:3.8 (RHSA-2023:4038)
- 241791 Red Hat Update for python38:3.8 and python38-devel:3.8 (RHSA-2023:4032)
- 241836 Red Hat Update for python3.9 (RHSA-2023:4203)
- 242344 Red Hat Update for rh-python38-python (RHSA-2023:6793)
- 257238 CentOS Security Update for python3 (CESA-2023:3556)
- 257239 CentOS Security Update for python (CESA-2023:3555)
- 283830 Fedora Security Update for mingw (FEDORA-2023-406c1c6ed7)
- 283831 Fedora Security Update for mingw (FEDORA-2023-b3a3df39dd)
- 283998 Fedora Security Update for python3.11 (FEDORA-2023-63c69aa712)
- 284004 Fedora Security Update for python2.7 (FEDORA-2023-953c2607d8)
- 284012 Fedora Security Update for python3.6 (FEDORA-2023-56cefa23df)
- 284015 Fedora Security Update for pypy3.8 (FEDORA-2023-d294ef140e)
- 284016 Fedora Security Update for pypy3.9 (FEDORA-2023-401947eb94)
- 284017 Fedora Security Update for pypy (FEDORA-2023-acdfd145f2)
- 284018 Fedora Security Update for python3.9 (FEDORA-2023-03599274db)
- 284019 Fedora Security Update for python3.10 (FEDORA-2023-309cadedc6)
- 284020 Fedora Security Update for python3.8 (FEDORA-2023-31888c4781)
- 284029 Fedora Security Update for python3.7 (FEDORA-2023-dd526ed2e4)
- 284067 Fedora Security Update for python3.7 (FEDORA-2023-f52390b9d2)
- 284068 Fedora Security Update for python3.7 (FEDORA-2023-75c4fc87fc)
- 284082 Fedora Security Update for pypy (FEDORA-2023-690e150a39)
- 284083 Fedora Security Update for pypy3.9 (FEDORA-2023-31b242abfa)
- 284084 Fedora Security Update for pypy (FEDORA-2023-4f1864b5cb)
- 284085 Fedora Security Update for pypy3.9 (FEDORA-2023-81bb8e3b99)
- 284086 Fedora Security Update for python3.9 (FEDORA-2023-b854908745)
- 284087 Fedora Security Update for python3.10 (FEDORA-2023-d1cdb80702)
- 284088 Fedora Security Update for python3.10 (FEDORA-2023-994ecd7dbc)
- 284089 Fedora Security Update for python3.9 (FEDORA-2023-71dc071847)
- 284091 Fedora Security Update for python3.8 (FEDORA-2023-d8b0003ecd)
- 284092 Fedora Security Update for python3.8 (FEDORA-2023-6382c223a5)
- 284093 Fedora Security Update for python3.6 (FEDORA-2023-2b25dd2a11)
- 284094 Fedora Security Update for python3.6 (FEDORA-2023-2415ca21a4)
- 284097 Fedora Security Update for python2.7 (FEDORA-2023-7cdb3b48f1)
- 284098 Fedora Security Update for python2.7 (FEDORA-2023-96aa33f0d3)
- 284100 Fedora Security Update for python3.11 (FEDORA-2023-1092538441)
- 285297 Fedora Security Update for pypy3.10 (FEDORA-2023-ddde191e04)
- 330145 IBM AIX Security Restrictions Bypass due to Python (python_advisory5)
- 354792 Amazon Linux Security Advisory for python : ALAS2-2023-1980
- 354817 Amazon Linux Security Advisory for python3 : ALAS2-2023-1990
- 354857 Amazon Linux Security Advisory for python27 : ALAS-2023-1713
- 354865 Amazon Linux Security Advisory for python38 : ALAS-2023-1714
- 355066 Amazon Linux Security Advisory for python27 : AL2012-2023-390
- 355271 Amazon Linux Security Advisory for python3.9 : ALAS2023-2023-116
- 356223 Amazon Linux Security Advisory for python38 : ALASPYTHON3.8-2023-001
- 356476 Amazon Linux Security Advisory for python38 : ALAS2PYTHON3.8-2023-001
- 357037 Amazon Linux Security Advisory for python3.11 : ALAS2023-2024-500
- 378622 Alibaba Cloud Linux Security Update for python3 (ALINUX2-SA-2023:0027)
- 378624 Alibaba Cloud Linux Security Update for python3 (ALINUX3-SA-2023:0053)
- 379050 Splunk Enterprise Multiple Vulnerabilities (SVD-2023-1104,SVD-2023-1105)
- 379095 Splunk Universal Forwarder Multiple Vulnerabilities (SVD-2023-1107)
- 6000148 Debian Security Update for python2.7 (DLA 3575-1)
- 672919 EulerOS Security Update for python3 (EulerOS-SA-2023-1826)
- 672924 EulerOS Security Update for python3 (EulerOS-SA-2023-1808)
- 673193 EulerOS Security Update for python3 (EulerOS-SA-2023-2339)
- 673207 EulerOS Security Update for python3 (EulerOS-SA-2023-2319)
- 673632 EulerOS Security Update for python3 (EulerOS-SA-2023-2705)
- 673821 EulerOS Security Update for python3 (EulerOS-SA-2023-3150)
- 674043 EulerOS Security Update for python2 (EulerOS-SA-2023-3149)
- 674058 EulerOS Security Update for python3 (EulerOS-SA-2023-2663)
- 691183 Free Berkeley Software Distribution (FreeBSD) Security Update for python (d86becfe-05a4-11ee-9d4a-080027eda32c)
- 753748 SUSE Enterprise Linux Security Update for python3 (SUSE-SU-2023:0663-1)
- 753749 SUSE Enterprise Linux Security Update for python36 (SUSE-SU-2023:0662-1)
- 753766 SUSE Enterprise Linux Security Update for python39 (SUSE-SU-2023:0707-1)
- 753769 SUSE Enterprise Linux Security Update for python (SUSE-SU-2023:0724-1)
- 753771 SUSE Enterprise Linux Security Update for python3 (SUSE-SU-2023:0736-1)
- 753837 SUSE Enterprise Linux Security Update for python3 (SUSE-SU-2023:0868-1)
- 754166 SUSE Enterprise Linux Security Update for python (SUSE-SU-2023:2639-1)
- 754211 SUSE Enterprise Linux Security Update for python39 (SUSE-SU-2023:2957-1)
- 755855 SUSE Enterprise Linux Security Update for python311 (SUSE-SU-2023:2937-1)
- 905625 Common Base Linux Mariner (CBL-Mariner) Security Update for python3 (13679)
- 905628 Common Base Linux Mariner (CBL-Mariner) Security Update for python2 (13699)
- 906548 Common Base Linux Mariner (CBL-Mariner) Security Update for python2 (13699-1)
- 906550 Common Base Linux Mariner (CBL-Mariner) Security Update for python3 (13679-1)
- 906587 Common Base Linux Mariner (CBL-Mariner) Security Update for python2 (13699-3)
- 906593 Common Base Linux Mariner (CBL-Mariner) Security Update for python3 (13679-3)
- 906780 Common Base Linux Mariner (CBL-Mariner) Security Update for python3 (13679-5)
- 906784 Common Base Linux Mariner (CBL-Mariner) Security Update for python2 (13699-5)
- 907380 Common Base Linux Mariner (CBL-Mariner) Security Update for python3 (31165)
- 907490 Common Base Linux Mariner (CBL-Mariner) Security Update for python3 (31165-1)
- 941139 AlmaLinux Security Update for python3.11 (ALSA-2023:3594)
- 941141 AlmaLinux Security Update for python3 (ALSA-2023:3591)
- 941144 AlmaLinux Security Update for python3.9 (ALSA-2023:3595)
- 941146 AlmaLinux Security Update for python3.11 (ALSA-2023:3585)
- 941162 AlmaLinux Security Update for python38:3.8 and python38-devel:3.8 (ALSA-2023:3781)
- 941163 AlmaLinux Security Update for python39:3.9 and python39-devel:3.9 (ALSA-2023:3811)
- 941164 AlmaLinux Security Update for python27:2.7 (ALSA-2023:3780)
- 960946 Rocky Linux Security Update for python3 (RLSA-2023:3591)
- 960950 Rocky Linux Security Update for python27:2.7 (RLSA-2023:3780)