CVE-2020-28463 log
Source |
|
Severity | Medium |
Remote | Yes |
Type | Url request injection |
Description | All versions of package python-reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce risk, use trustedSchemes & trustedHosts (see in Reportlab's documentation). |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-1592 | python-reportlab | 3.5.54-1 | 3.5.55-1 | Medium | Fixed |
References |
---|
https://snyk.io/vuln/SNYK-PYTHON-REPORTLAB-1022145 https://github.com/advisories/GHSA-mpvw-25mg-59vx |