QID 983211
QID 983211: Python (pip) Security Update for xmpp-http-upload (GHSA-hwv5-w8gm-fq9f)
Security update has been released for xmpp-http-upload to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
PR #12 fixes the issue. The PR has been merged into version 0.4.0 and 0.4.0 has been released and pushed to PyPI. Users are advised to upgrade immediately.Workaround:
- Apache can apparently be configured to filter such malicious paths when reverse-proxying.
- There are no other workarounds known.
- Apache can apparently be configured to filter such malicious paths when reverse-proxying.
- There are no other workarounds known.
Vendor References
- GHSA-hwv5-w8gm-fq9f -
github.com/advisories/GHSA-hwv5-w8gm-fq9f
CVEs related to QID 983211
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hwv5-w8gm-fq9f | xmpp-http-upload |
|