QID 981992
QID 981992: Python (pip) Security Update for pypiserver (GHSA-mh24-7wvg-v88g)
CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-mh24-7wvg-v88g for updates pertaining to this vulnerability.
Vendor References
- GHSA-mh24-7wvg-v88g -
github.com/advisories/GHSA-mh24-7wvg-v88g
CVEs related to QID 981992
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mh24-7wvg-v88g | pypiserver |
|