🚨 Critical Python URL parsing flaw (CVE-2023-24329) discovered! Allows domain filter bypass, enabling file reads & command execution.
Find details here: https://thehackernews.com/2023/08/new-python-url-parsing-flaw-enables.html
🚨 Critical Python URL parsing flaw (CVE-2023-24329) discovered! Allows domain filter bypass, enabling file reads & command execution.
Find details here: https://thehackernews.com/2023/08/new-python-url-parsing-flaw-enables.html
upgrade you python to new new version.
It has been addressed in the following versions:
>= 3.12
3.11.x >= 3.11.4
3.10.x >= 3.10.12
3.9.x >= 3.9.17
3.8.x >= 3.8.17, and
3.7.x >= 3.7.17
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.