Vulnerability PYSEC-2022-269

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
4 years ago
September 09, 2022 at 09:15 PM UTC
No summary available
3.1.1 - 3.2.0
3.1.1 - 3.2.0

Details

OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malicious redirect uri can cause denial of service. An attacker can also leverage usage of uri_validate functions depending where it is used. OAuthLib applications using OAuth2.0 provider support or use directly uri_validate are affected by this issue. Version 3.2.1 contains a patch. There are no known workarounds.

Impacted packages

Timeline

Published
4 years ago
September 09, 2022 at 09:15 PM UTC
Fixed (3.2.1)
4 years ago
September 09, 2022 at 08:15 PM UTC
Last Modified
2 years ago
November 08, 2023 at 04:10 AM UTC