PT-2022-5665 · Encode Oss+2 · Httpx+2
Lebr0Nlio
·
Published
2022-04-28
·
Updated
2025-01-18
·
CVE-2021-41945
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Encode OSS httpx versions < 0.23.0
Encode OSS httpx version <=1.0.0.beta0
Description
The issue is related to insufficient input validation in the
httpx.URL and httpx.Client components, as well as in some functions that utilize httpx.URL.copy with. This could potentially allow a remote attacker to bypass existing security restrictions.Recommendations
For Encode OSS httpx versions < 0.23.0, update to version 0.23.0 or later to resolve the issue.
For Encode OSS httpx version <=1.0.0.beta0, update to a version later than 1.0.0.beta0 to resolve the issue.
As a temporary workaround, consider restricting the use of
httpx.URL and httpx.Client until a patch is available. Avoid using functions that utilize httpx.URL.copy with in the affected API endpoints until the issue is resolved.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Httpx