CVE-2019-10751

Name
CVE-2019-10751
Description
All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a request from HTTP to a crafted URL pointing to a server in his or hers control.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://snyk.io/vuln/SNYK-PYTHON-HTTPIE-460107
Release Notes https://github.com/jakubroztocil/httpie/releases/tag/1.0.3
SUSE http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00003.html
SUSE http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00022.html
MLIST https://lists.debian.org/debian-lts-announce/2019/09/msg00031.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:httpie:httpie:*:*:*:*:*:*:*:* httpie == None == None

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
httpie 3.14-community 2.4.0-r3 Fabian Affolter <fabian@affolter-engineering.ch> fixed
httpie 3.15-community 2.5.0-r1 Fabian Affolter <fabian@affolter-engineering.ch> fixed
httpie 3.16-community 3.2.1-r0 Fabian Affolter <fabian@affolter-engineering.ch> fixed
httpie 3.17-community 3.2.1-r1 Fabian Affolter <fabian@affolter-engineering.ch> fixed
httpie 3.18-community 3.2.1-r4 Fabian Affolter <fabian@affolter-engineering.ch> fixed
httpie 3.19-community 3.2.2-r0 Fabian Affolter <fabian@affolter-engineering.ch> fixed
httpie edge-community 3.2.2-r2 fossdd <fossdd@pwned.life> fixed