CVE-2020-28463 log
| Source |
|
| Severity | Medium |
| Remote | Yes |
| Type | Url request injection |
| Description | All versions of package python-reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce risk, use trustedSchemes & trustedHosts (see in Reportlab's documentation). |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-1592 | python-reportlab | 3.5.54-1 | 3.5.55-1 | Medium | Fixed |
| References |
|---|
https://snyk.io/vuln/SNYK-PYTHON-REPORTLAB-1022145 https://github.com/advisories/GHSA-mpvw-25mg-59vx |