CVE-2023-24329: Fedoraproject Fedora
High severity, CVSS 7.5. EPSS: 20.5% chance of exploitation in the next 30 days.
An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
Affected products
- Fedoraproject Fedora: version 36 only; version 37 only; version 38 only
- Netapp Active Iq Unified Manager: affected versions not specified
- Netapp Management Services For Element Software: affected versions not specified
- Netapp Management Services For Netapp Hci: affected versions not specified
- Netapp Ontap Select Deploy Administration Utility: affected versions not specified
- Python Python: before 3.7.17 (fixed in 3.7.17); from 3.8.0, before 3.8.17 (fixed in 3.8.17); from 3.9.0, before 3.9.17 (fixed in 3.9.17); from 3.10.0, before 3.10.12 (fixed in 3.10.12); from 3.11.0, before 3.11.4 (fixed in 3.11.4)
Published 2023-02-17. Last modified 2026-06-17.