{"id":"GHSA-rw83-v3pw-m362","summary":"Withdrawn: safeurl-python contains Server-Side Request Forgery","details":"## Withdrawn\n\nThis advisory has been withdrawn as a duplicate of [GHSA-jgh8-vchw-q3g7](https://github.com/advisories/GHSA-jgh8-vchw-q3g7).\n\n## Original Description\n\nisInList in the safeurl-python package before 1.2 for Python has an insufficiently restrictive regular expression for external domains, leading to SSRF.","modified":"2024-12-03T06:08:55.973162Z","published":"2023-01-30T06:30:27Z","withdrawn":"2023-02-01T20:04:51Z","database_specific":{"cwe_ids":["CWE-918"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-02-01T20:04:51Z","nvd_published_at":"2023-01-30T05:15:00Z"},"references":[{"type":"WEB","url":"https://github.com/IncludeSecurity/safeurl-python/security/advisories/GHSA-jgh8-vchw-q3g7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-24622"},{"type":"PACKAGE","url":"https://github.com/IncludeSecurity/safeurl-python"}],"affected":[{"package":{"name":"safeurl-python","ecosystem":"PyPI","purl":"pkg:pypi/safeurl-python"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2"}]}],"versions":["1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-rw83-v3pw-m362/GHSA-rw83-v3pw-m362.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}