CVE-2020-28463 log

Source
Severity Medium
Remote Yes
Type Url request injection
Description
All versions of package python-reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce risk, use trustedSchemes & trustedHosts (see in Reportlab's documentation).
Group Package Affected Fixed Severity Status Ticket
AVG-1592 python-reportlab 3.5.54-1 3.5.55-1 Medium Fixed
References
https://snyk.io/vuln/SNYK-PYTHON-REPORTLAB-1022145
https://github.com/advisories/GHSA-mpvw-25mg-59vx