Skip to content

Arbitrary Argument Injection SNYK-RHEL9-PYTHON3-15760267 #8850

@github-actions

Description

@github-actions

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3 package and not the python3 package as distributed by RHEL.
See How to fix? for RHEL:9 relevant fixed versions and status.

The webbrowser.open() API would accept leading dashes in the URL which
could be handled as command line options for certain web browsers. New
behavior rejects leading dashes. Users are recommended to sanitize URLs
prior to passing to webbrowser.open().

Remediation

There is no fixed version for RHEL:9 python3.

References

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions