Recurly vulnerable to SSRF
Critical severity
GitHub Reviewed
Published
Jan 4, 2019
to the GitHub Advisory Database
•
Updated Oct 26, 2024
Package
Affected versions
>= 2.6.0, < 2.6.2
= 2.5.0
>= 2.4.0, < 2.4.5
= 2.3.0
>= 2.2.0, < 2.2.22
>= 2.1.0, < 2.1.16
< 2.0.5
Patched versions
2.6.2
2.5.1
2.4.5
2.3.1
2.2.22
2.1.16
2.0.5
Description
Published to the GitHub Advisory Database
Jan 4, 2019
Reviewed
Jun 16, 2020
Last updated
Oct 26, 2024
The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the
Resource.get
method that could result in compromise of API keys or other critical resources.References