Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
OAuthLib vulnerable DoS when attacker provides malicious IPV6 URI
Vulnerability Description
OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malicious redirect uri can cause denial of service. An attacker can also leverage usage of `uri_validate` functions depending where it is used. OAuthLib applications using OAuth2.0 provider support or use directly `uri_validate` are affected by this issue. Version 3.2.1 contains a patch. There are no known workarounds.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Vulnerability Type
输入验证不恰当
Vulnerability Title
OAuthLib 输入验证错误漏洞
Vulnerability Description
OAuthLib是OAuthLib开源的一个 OAuth1 和 OAuth2 的 Python 框架。 OAuthLib 3.1.1版本至3.2.1版本存在输入验证错误漏洞。攻击者利用该漏洞提供恶意重定向uri可导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A