QID 997207
Date Published: 2024-02-12
QID 997207: Python (Pip) Security Update for paste (GHSA-7gfc-2v6g-6w9f)
Multiple cross-site scripting (XSS) vulnerabilities in the paste.httpexceptions implementation in Paste before 1.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving a 404 status code, related to (1) paste.urlparser.StaticURLParser, (2) paste.urlparser.PkgResourcesParser, (3) paste.urlmap.URLMap, and (4) HTTPNotFound.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-7gfc-2v6g-6w9f for updates and patch information.
Vendor References
- GHSA-7gfc-2v6g-6w9f -
github.com/advisories/GHSA-7gfc-2v6g-6w9f
CVEs related to QID 997207
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7gfc-2v6g-6w9f | paste |
|