GithubHelp home page GithubHelp logo

k5924's Introduction

Header

Connect with me:

element/matrix codewars exercism stackoverflow

⚑ General Stats

Metrics

πŸ“š Learning Stats

roadmap.sh

β™ŸοΈ Chess Stats
Type Rapid ⏲️ Blitz ⚑ Bullet πŸ”«
Current 285 No Rating No Rating
Best 296 No Rating No Rating
White βšͺ Black ⚫ Result πŸ† Date πŸ“… Position πŸ—ΊοΈ Type πŸ••
yttr1x Karens11 win πŸ₯‡ 8/12/2022 Link Rapid
x-9016632113 yttr1x win πŸ₯‡ 6/12/2022 Link Rapid
thienkhang09358 yttr1x checkmated ❌ 3/12/2022 Link Rapid
yttr1x theThristywo checkmated ❌ 1/12/2022 Link Rapid
Spicymayo10 yttr1x insufficient ⏸️ 30/11/2022 Link Rapid
yttr1x Hqzeee win πŸ₯‡ 30/11/2022 Link Rapid
bigmode55 yttr1x checkmated ❌ 28/11/2022 Link Rapid
yttr1x EliteBestChessPlayer checkmated ❌ 27/11/2022 Link Rapid
β˜‘οΈ Todoist Stats πŸ† 13,167 Karma Points 🌸 Completed 0 tasks today βœ… Completed 1,594 tasks so far ⏳ Longest streak is 11 days

Counter

k5924's People

Contributors

actions-user avatar example avatar github-actions[bot] avatar k5924 avatar mend-bolt-for-github[bot] avatar

Watchers

 avatar

k5924's Issues

CVE-2021-33503 (High) detected in urllib3-1.25.11-py2.py3-none-any.whl - autoclosed

CVE-2021-33503 - High Severity Vulnerability

Vulnerable Library - urllib3-1.25.11-py2.py3-none-any.whl

HTTP library with thread-safe connection pooling, file post, and more.

Library home page: https://files.pythonhosted.org/packages/56/aa/4ef5aa67a9a62505db124a5cb5262332d1d4153462eb8fd89c9fa41e5d92/urllib3-1.25.11-py2.py3-none-any.whl

Path to dependency file: k5924/api/requirements.txt

Path to vulnerable library: k5924/api/requirements.txt

Dependency Hierarchy:

  • requests-2.24.0-py2.py3-none-any.whl (Root Library)
    • ❌ urllib3-1.25.11-py2.py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: 76a83ec765fd4a3e2e034dc3373eebb11a88ae82

Found in base branch: main

Vulnerability Details

An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.

Publish Date: 2021-06-29

URL: CVE-2021-33503

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-q2q7-5pp4-w6pg

Release Date: 2021-05-22

Fix Resolution: urllib3 - 1.26.5


Step up your Open Source Security Game with WhiteSource here

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    πŸ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. πŸ“ŠπŸ“ˆπŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❀️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.