VYPR

rpm package

opensuse/python-yarl&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/python-yarl&distro=openSUSE%20Tumbleweed

Vulnerabilities (2)

  • CVE-2023-24329HigFeb 17, 2023
    affected < 1.8.2-3.1fixed 1.8.2-3.1

    An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.

  • CVE-2021-23336MedFeb 15, 2021
    affected < 1.24.5-1.1fixed 1.24.5-1.1

    The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When