Bug ID 1213006
Summary VUL-0: CVE-2023-34457: python-MechanicalSoup: malicious web server can read arbitrary files on client using file input inside HTML form
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.4
Hardware Other
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee toddrme2178@gmail.com
Reporter carlos.lopez@suse.com
QA Contact security-team@suse.de
Target Milestone ---
Found By ---
Blocker ---

CVE-2023-34457

A malicious web server can read arbitrary files on the client using a <input
type="file" ...> inside HTML form. All users of MechanicalSoup's form
submission are affected, unless they took very specific (and manual) steps to
reset HTML form field values.

https://github.com/MechanicalSoup/MechanicalSoup/security/advisories/GHSA-x456-3ccm-m6j4

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-34457
https://bugzilla.redhat.com/show_bug.cgi?id=2219755


You are receiving this mail because: