GHSA-r82c-j4mq-5xfw

Suggest an improvement
Source
https://github.com/advisories/GHSA-r82c-j4mq-5xfw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/10/GHSA-r82c-j4mq-5xfw/GHSA-r82c-j4mq-5xfw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-r82c-j4mq-5xfw
Published
2020-10-27T19:19:56Z
Modified
2024-12-02T05:51:37Z
Summary
Update bitlyshortener to >=0.5.0 to prevent generating some invalid short URLs
Details

Impact

Due to a sudden upstream breaking change by Bitly, versions of bitlyshortener <0.5.0 can generate an invalid short URL when a vanity domain exists.

Patches

Upgrading bitlyshortener to 0.5.0 or newer will prevent the generation of any such invalid short URLs.

References

Database specific
{
    "cwe_ids":  [
        "CWE-601"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-10-27T19:19:44Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

PyPI / bitlyshortener

Package

Name
bitlyshortener
View open source insights on deps.dev
Purl
pkg:pypi/bitlyshortener

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.5.0

Affected versions

0.*
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.4.0
0.4.1
0.4.2
0.4.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/10/GHSA-r82c-j4mq-5xfw/GHSA-r82c-j4mq-5xfw.json"