PYSEC-2010-29

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/paste/PYSEC-2010-29.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2010-29
Aliases
Published
2010-11-06T00:00:00Z
Modified
2024-02-08T16:11:39.061601Z
Summary
[none]
Details

Multiple cross-site scripting (XSS) vulnerabilities in the paste.httpexceptions implementation in Paste before 1.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving a 404 status code, related to (1) paste.urlparser.StaticURLParser, (2) paste.urlparser.PkgResourcesParser, (3) paste.urlmap.URLMap, and (4) HTTPNotFound.

References

Affected packages

PyPI / paste

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.7.4

Affected versions

0.*

0.3
0.4
0.4.1
0.5
0.9
0.9.1
0.9.2
0.9.3
0.9.5
0.9.6
0.9.7
0.9.8
0.9.8.1

1.*

1.0
1.0.1
1.1
1.1.1
1.2
1.2.1
1.3
1.4
1.4.1
1.4.2
1.5
1.5.1
1.6
1.7
1.7.1
1.7.2
1.7.3
1.7.3.1