Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.4 PyPI

rdiffweb vulnerable to Special Element Injection

GHSA-83pm-7v48-5jp4 · CVE-2022-4721 · PYSEC-2022-43007

Published · Modified

Description

In rdiffweb prior to 2.5.5, lack of sanitisation of characters in SSH key name could allow attacker to inject a hyperlink injection that could allow attacker to redirect victim to malicious websites.

Ready to move

Start Securing

Free, no credit card | First findings in minutes