CVE-2024-11168 - Apache Urllib Host Validation Bypass

1 week ago 4
ARTICLE AD BOX
CVE ID : CVE-2024-11168
Published : Nov. 12, 2024, 10:15 p.m. | 24 minutes ago
Description : The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article