High severityNVD Advisory· Published Aug 23, 2019· Updated Aug 4, 2024
CVE-2019-10751
CVE-2019-10751
Description
All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a request from HTTP to a crafted URL pointing to a server in his or hers control.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
httpiePyPI | < 1.0.3 | 1.0.3 |
Affected products
9- HTTPie/HTTPie packagedescription
- osv-coords8 versionspkg:apk/chainguard/httpiepkg:apk/chainguard/httpie-docpkg:apk/wolfi/httpiepkg:apk/wolfi/httpie-docpkg:pypi/httpiepkg:rpm/opensuse/httpie&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/httpie&distro=openSUSE%20Tumbleweedpkg:rpm/suse/httpie&distro=SUSE%20Package%20Hub%2015%20SP1
< 0+ 7 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 1.0.3
- (no CPE)range: < 1.0.3-bp151.2.3.1
- (no CPE)range: < 2.5.0-1.2
- (no CPE)range: < 1.0.3-bp151.2.3.1
Patches
Vulnerability mechanics
References
8- lists.opensuse.org/opensuse-security-announce/2019-09/msg00003.htmlghsavendor-advisoryx_refsource_SUSEWEB
- lists.opensuse.org/opensuse-security-announce/2019-09/msg00022.htmlghsavendor-advisoryx_refsource_SUSEWEB
- github.com/advisories/GHSA-xjjg-vmw6-c2p9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-10751ghsaADVISORY
- github.com/jakubroztocil/httpie/releases/tag/1.0.3ghsax_refsource_MISCWEB
- github.com/pypa/advisory-database/tree/main/vulns/httpie/PYSEC-2019-23.yamlghsaWEB
- lists.debian.org/debian-lts-announce/2019/09/msg00031.htmlghsamailing-listx_refsource_MLISTWEB
- snyk.io/vuln/SNYK-PYTHON-HTTPIE-460107ghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.