Python-Multipart to parser streamingowy dla multipart w Pythonie. Przed wersją 0.0.30 QuerystringParser traktował znak ; jako separator pól w телach application/x-www-form-urlencoded, oprócz &. Standard WHATWG URL, nowoczesne przeglądarki i urllib.parse Pythona (od poprawki CVE-2021-23336) traktują tylko & jako separator. Tworzy to różnicę parserów: te same bajty są tokenizowane na różne pola niż by wytworzyła zgodna ze standardem WHATWG pośrednia komponenta, umożliwiając atakującemu smugglowanie dodatkowych pól formularza obok upstream'owego komponentu inspekcji ciała. Podatność ta została naprawiona w wersji 0.0.30.
▸ Pokaż oryginał (EN)
Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATWG URL standard, modern browsers, and Python's urllib.parse (since the CVE-2021-23336 fix) treat only & as a separator. This creates a parser differential: the same bytes are tokenized into different fields than a WHATWG compliant intermediary would produce, allowing an attacker to smuggle extra form fields past an upstream body inspecting component. This vulnerability is fixed in 0.0.30.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NFastapiexpert Python Multipart
APPFastapiexpert< 0.0.30
Powiązane podatności
Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-f...
Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnera...
`python-multipart` is a streaming multipart parser for Python. When using form data, `python-multipart` uses a...
Python-Multipart to parser streamingowy multipart dla Pythona. Wersje wcześniejsze niż 0.0.26 mają podatność D...
Python-Multipart to parser strumieni multipart dla Pythona. Przed wersją 0.0.30 funkcja parse_options_header a...