{"id":"GHSA-38rv-5jqc-m2cv","summary":"Recurly vulnerable to SSRF","details":"The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the `Resource.get` method that could result in compromise of API keys or other critical resources.","aliases":["CVE-2017-0906","PYSEC-2017-68"],"modified":"2024-10-26T18:50:44.966235Z","published":"2019-01-04T17:48:09Z","database_specific":{"github_reviewed_at":"2020-06-16T20:54:38Z","nvd_published_at":null,"cwe_ids":["CWE-918"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-0906"},{"type":"WEB","url":"https://github.com/recurly/recurly-client-python/commit/049c74699ce93cf126feff06d632ea63fba36742"},{"type":"WEB","url":"https://hackerone.com/reports/288635"},{"type":"WEB","url":"https://dev.recurly.com/page/python-updates"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-38rv-5jqc-m2cv"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/recurly/PYSEC-2017-68.yaml"}],"affected":[{"package":{"name":"recurly","ecosystem":"PyPI","purl":"pkg:pypi/recurly"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.0"},{"fixed":"2.6.2"}]}],"versions":["2.6.0","2.6.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/01/GHSA-38rv-5jqc-m2cv/GHSA-38rv-5jqc-m2cv.json"}},{"package":{"name":"recurly","ecosystem":"PyPI","purl":"pkg:pypi/recurly"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.5.0"},{"fixed":"2.5.1"}]}],"versions":["2.5.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/01/GHSA-38rv-5jqc-m2cv/GHSA-38rv-5jqc-m2cv.json"}},{"package":{"name":"recurly","ecosystem":"PyPI","purl":"pkg:pypi/recurly"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.4.0"},{"fixed":"2.4.5"}]}],"versions":["2.4.0","2.4.1","2.4.2","2.4.3","2.4.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/01/GHSA-38rv-5jqc-m2cv/GHSA-38rv-5jqc-m2cv.json"}},{"package":{"name":"recurly","ecosystem":"PyPI","purl":"pkg:pypi/recurly"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.3.0"},{"fixed":"2.3.1"}]}],"versions":["2.3.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/01/GHSA-38rv-5jqc-m2cv/GHSA-38rv-5jqc-m2cv.json"}},{"package":{"name":"recurly","ecosystem":"PyPI","purl":"pkg:pypi/recurly"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.2.0"},{"fixed":"2.2.22"}]}],"versions":["2.2.0","2.2.1","2.2.10","2.2.11","2.2.12","2.2.13","2.2.14","2.2.15","2.2.16","2.2.17","2.2.18","2.2.19","2.2.2","2.2.20","2.2.21","2.2.3","2.2.4","2.2.6","2.2.7","2.2.8","2.2.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/01/GHSA-38rv-5jqc-m2cv/GHSA-38rv-5jqc-m2cv.json"}},{"package":{"name":"recurly","ecosystem":"PyPI","purl":"pkg:pypi/recurly"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.0"},{"fixed":"2.1.16"}]}],"versions":["2.1.0","2.1.1","2.1.10","2.1.11","2.1.12","2.1.13","2.1.14","2.1.15","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8","2.1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/01/GHSA-38rv-5jqc-m2cv/GHSA-38rv-5jqc-m2cv.json"}},{"package":{"name":"recurly","ecosystem":"PyPI","purl":"pkg:pypi/recurly"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.5"}]}],"versions":["2.0.0","2.0.2","2.0.3","2.0.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/01/GHSA-38rv-5jqc-m2cv/GHSA-38rv-5jqc-m2cv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}