Description
urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call.
Remediation
References
Related Vulnerabilities
WordPress 5.2.x Prototype Pollution (5.2 - 5.2.14)
Django Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-6975)
XWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-32731)
Oracle HTTP Server Improper Access Control Vulnerability (CVE-2026-34291)