« Volver al listado

CVE-2017-0906

Estado: ModificadaCrítica (9.8)—

The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource.get" method that could result in compromise of API keys or other critical resources.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-0906",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "support@hackerone.com",
      "affectedData": [
        {
          "vendor": "Recurly",
          "product": "recurly python module",
          "versions": [
            {
              "status": "affected",
              "version": "Versions before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-11-13T17:29:00.457",
  "references": [
    {
      "url": "https://dev.recurly.com/page/python-updates",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://github.com/recurly/recurly-client-python/commit/049c74699ce93cf126feff06d632ea63fba36742",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://hackerone.com/reports/288635",
      "tags": [
        "Permissions Required"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://dev.recurly.com/page/python-updates",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/recurly/recurly-client-python/commit/049c74699ce93cf126feff06d632ea63fba36742",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://hackerone.com/reports/288635",
      "tags": [
        "Permissions Required"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "support@hackerone.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-918"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-918"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the \"Resource.get\" method that could result in compromise of API keys or other critical resources."
    },
    {
      "lang": "es",
      "value": "La biblioteca de Python Recurly Client en versiones anteriores a la 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1 y 2.6.2 es vulnerable a Server-Side Request Forgery en el método \"Resource.get\" que podría conllevar el compromiso de las claves API o de otros recursos críticos."
    }
  ],
  "lastModified": "2026-06-17T00:58:30.330",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:recurly:recurly_client_python:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "557D1B51-6392-4527-B1E3-2090E32CA9EF",
              "versionEndIncluding": "2.0.4",
              "versionStartIncluding": "2.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:recurly:recurly_client_python:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "40615C43-B326-44B4-A5AE-E2F70A44B8C7",
              "versionEndIncluding": "2.1.15",
              "versionStartIncluding": "2.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:recurly:recurly_client_python:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6EB0197-8002-48CC-AC2F-86C81F75BB96",
              "versionEndIncluding": "2.2.21",
              "versionStartIncluding": "2.2.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:recurly:recurly_client_python:2.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "703E03AB-A209-427E-AF2A-733AE854C038"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:recurly:recurly_client_python:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "29D290C7-CC59-4AA8-9CFD-936ED5E388B1",
              "versionEndIncluding": "2.4.4",
              "versionStartIncluding": "2.4.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:recurly:recurly_client_python:2.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "12D506D9-3FE7-4775-BA47-EF65D67ACF25"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:recurly:recurly_client_python:2.6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36D3D568-796D-4AAC-B44B-E01DBF470E24"
            },
            {
              "criteria": "cpe:2.3:a:recurly:recurly_client_python:2.6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "15EA0F95-0F90-4B0A-9CDB-E2EB8E4773A9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "support@hackerone.com"
}