Improper input validation of octal strings in Python...
Critical severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated May 12, 2023
Description
Published by the National Vulnerability Database
May 6, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
May 12, 2023
Improper input validation of octal strings in Python stdlib ipaddress 3.10 and below allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many programs that rely on Python stdlib ipaddress. IP address octects are left stripped instead of evaluated as valid IP addresses.
References