← Back

CVE-2017-0906

nvd nist
Published: Nov 13, 2017Modified: May 13, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource.get" method that could result in compromise of API keys or other critical resources.

Affected (8)

1 product
Recurly Client Python
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2.0.0 to 2.0.4
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2.1.0 to 2.1.15
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2.2.0 to 2.2.21
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.3.0
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2.4.0 to 2.4.4
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.5.0
Configuration G
2 vulnerable
Vulnerable SoftwareAffected Versions
Recurly
Version 2.6.0
Version 2.6.1

References (6)

Source: support@hackerone.com
Vendor Advisory
Source: support@hackerone.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required

Timeline

No history available yet.