CVE-2019-10751

All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a request from HTTP to a crafted URL pointing to a server in his or hers control.
References
Link Resource
https://snyk.io/vuln/SNYK-PYTHON-HTTPIE-460107 Exploit Third Party Advisory Exploit Exploit Third Party Advisory Third Party Advisory
https://github.com/jakubroztocil/httpie/releases/tag/1.0.3 Release Notes Third Party Advisory Release Notes Release Notes Third Party Advisory Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00022.html
https://lists.debian.org/debian-lts-announce/2019/09/msg00031.html
Configurations

Configuration 1 (hide)

cpe:2.3:a:httpie:httpie:*:*:*:*:*:*:*:*

Information

Published : 2019-08-23 17:15

Updated : 2019-09-02 18:15


NVD link : CVE-2019-10751

Mitre link : CVE-2019-10751


JSON object : View

Products Affected

httpie

  • httpie
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')