{ "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", "CVE_data_meta": { "ID": "CVE-2024-11168", "ASSIGNER": "cna@python.org", "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", "value": "The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "affects": { "vendor": { "vendor_data": [ { "vendor_name": "Python Software Foundation", "product": { "product_data": [ { "product_name": "CPython", "version": { "version_data": [ { "version_affected": "<", "version_name": "0", "version_value": "3.9.21" }, { "version_affected": "<", "version_name": "3.10.0", "version_value": "3.10.16" }, { "version_affected": "<", "version_name": "3.11.0", "version_value": "3.11.4" }, { "version_affected": "<", "version_name": "3.12.0a1", "version_value": "3.12.0b1" } ] } } ] } } ] } }, "references": { "reference_data": [ { "url": "https://github.com/python/cpython/commit/29f348e232e82938ba2165843c448c2b291504c5", "refsource": "MISC", "name": "https://github.com/python/cpython/commit/29f348e232e82938ba2165843c448c2b291504c5" }, { "url": "https://github.com/python/cpython/pull/103849", "refsource": "MISC", "name": "https://github.com/python/cpython/pull/103849" }, { "url": "https://github.com/python/cpython/issues/103848", "refsource": "MISC", "name": "https://github.com/python/cpython/issues/103848" }, { "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/XPWB6XVZ5G5KGEI63M4AWLIEUF5BPH4T/", "refsource": "MISC", "name": "https://mail.python.org/archives/list/security-announce@python.org/thread/XPWB6XVZ5G5KGEI63M4AWLIEUF5BPH4T/" }, { "url": "https://github.com/python/cpython/commit/b2171a2fd41416cf68afd67460578631d755a550", "refsource": "MISC", "name": "https://github.com/python/cpython/commit/b2171a2fd41416cf68afd67460578631d755a550" }, { "url": "https://github.com/python/cpython/commit/634ded45545ce8cbd6fd5d49785613dd7fa9b89e", "refsource": "MISC", "name": "https://github.com/python/cpython/commit/634ded45545ce8cbd6fd5d49785613dd7fa9b89e" }, { "url": "https://github.com/python/cpython/commit/ddca2953191c67a12b1f19d6bca41016c6ae7132", "refsource": "MISC", "name": "https://github.com/python/cpython/commit/ddca2953191c67a12b1f19d6bca41016c6ae7132" } ] }, "generator": { "engine": "Vulnogram 0.2.0" }, "source": { "discovery": "UNKNOWN" }, "credits": [ { "lang": "en", "value": "zer0yu (IPASSLab && ZGC Lab)" } ] }