This repository has been archived by the owner on Mar 11, 2024. It is now read-only.
CVE-2023-34457 (High) detected in MechanicalSoup-1.1.0-py3-none-any.whl #50
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2023-34457 - High Severity Vulnerability
Vulnerable Library - MechanicalSoup-1.1.0-py3-none-any.whl
A Python library for automating interaction with websites
Library home page: https://files.pythonhosted.org/packages/db/ae/244f73ee13f999811069fb4ef4b19b1ebf6b41b3ea5f1046645e51d949dc/MechanicalSoup-1.1.0-py3-none-any.whl
Path to dependency file: /tmp/ws-scm/kalel
Path to vulnerable library: /tmp/ws-scm/kalel
Dependency Hierarchy:
Found in base branch: master
Vulnerability Details
MechanicalSoup is a Python library for automating interaction with websites. Starting in version 0.2.0 and prior to version 1.3.0, a malicious web server can read arbitrary files on the client using a
<input type="file" ...>
inside HTML form. All users of MechanicalSoup's form submission are affected, unless they took very specific (and manual) steps to reset HTML form field values. Version 1.3.0 contains a patch for this issue.Publish Date: 2023-07-05
URL: CVE-2023-34457
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://www.cve.org/CVERecord?id=CVE-2023-34457
Release Date: 2023-07-05
Fix Resolution: MechanicalSoup - 1.3.0
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: