Description
urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call.
Remediation
References
Related Vulnerabilities
Oracle Application Server CVE-2008-3986 Vulnerability (CVE-2008-3986)
WordPress Plugin Export any WordPress data to XML/CSV Cross-Site Scripting (1.3.5)
MySQL CVE-2017-3651 Vulnerability (CVE-2017-3651)
Grafana Incorrect Authorization Vulnerability (CVE-2023-6152)
WordPress Plugin Cookie Information-Free GDPR Consent Solution Privilege Escalation (1.4.2)