All of lore.kernel.org
 help / color / mirror / Atom feed
* [meta-virtualization][scarthgap][PATCH 1/2] python3-webob: fix CVE-2024-42353
@ 2026-08-06  5:54 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
  2026-08-06  5:54 ` [meta-virtualization][scarthgap][PATCH 2/2] python3-webob: fix CVE-2026-44889 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
  2026-08-07 18:05 ` [meta-virtualization][scarthgap][PATCH 1/2] python3-webob: fix CVE-2024-42353 Bruce Ashfield
  0 siblings, 2 replies; 4+ messages in thread
From: Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-06  5:54 UTC (permalink / raw)
  To: meta-virtualization; +Cc: xe-linux-external, Darsh Kelaiya

From: Darsh Kelaiya <dkelaiya@cisco.com>

This patch applies the upstream fix as referenced in [2], using the
commit shown in [1].

[1] https://github.com/Pylons/webob/commit/f689bcf4f0a1f64f1735b1d5069aef5be6974b5b
[2] https://nvd.nist.gov/vuln/detail/CVE-2024-42353

Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
---
 .../python/python3-webob/CVE-2024-42353.patch | 56 +++++++++++++++++++
 .../python/python3-webob_1.8.7.bb             |  2 +
 2 files changed, 58 insertions(+)
 create mode 100644 recipes-devtools/python/python3-webob/CVE-2024-42353.patch

diff --git a/recipes-devtools/python/python3-webob/CVE-2024-42353.patch b/recipes-devtools/python/python3-webob/CVE-2024-42353.patch
new file mode 100644
index 00000000..56e7543f
--- /dev/null
+++ b/recipes-devtools/python/python3-webob/CVE-2024-42353.patch
@@ -0,0 +1,56 @@
+From a14a5b798de5b1145513660be64c09c7117f2b0d Mon Sep 17 00:00:00 2001
+From: Delta Regeer <xistence@0x58.com>
+Date: Wed, 7 Aug 2024 11:15:35 -0600
+Subject: [PATCH] Add fix for open redirect
+
+CVE: CVE-2024-42353
+Upstream-Status: Backport [https://github.com/Pylons/webob/commit/f689bcf4f0a1f64f1735b1d5069aef5be6974b5b]
+
+(cherry picked from commit f689bcf4f0a1f64f1735b1d5069aef5be6974b5b)
+Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
+---
+ src/webob/response.py  |  5 +++++
+ tests/test_response.py | 11 +++++++++++
+ 2 files changed, 16 insertions(+)
+
+diff --git a/src/webob/response.py b/src/webob/response.py
+index 2aad591..efc38ec 100644
+--- a/src/webob/response.py
++++ b/src/webob/response.py
+@@ -1284,6 +1284,11 @@ class Response(object):
+         if SCHEME_RE.search(value):
+             return value
+ 
++        # This is to fix an open redirect issue due to the way that
++        # urlparse.urljoin works. See CVE-2024-42353 and
++        # https://github.com/Pylons/webob/security/advisories/GHSA-mg3v-6m49-jhp3
++        if value.startswith("//"):
++            value = "/%2f{}".format(value[2:])
+         new_location = urlparse.urljoin(_request_uri(environ), value)
+         return new_location
+ 
+diff --git a/tests/test_response.py b/tests/test_response.py
+index 9d9f9d3..8a6ac06 100644
+--- a/tests/test_response.py
++++ b/tests/test_response.py
+@@ -1031,6 +1031,17 @@ def test_location():
+     assert req.get_response(res).location == 'http://localhost/test2.html'
+ 
+ 
++def test_location_no_open_redirect():
++    # This is a test for a fix for CVE-2024-42353 and
++    # https://github.com/Pylons/webob/security/advisories/GHSA-mg3v-6m49-jhp3
++    res = Response()
++    res.status = "301"
++    res.location = "//www.example.com/test"
++    assert res.location == "//www.example.com/test"
++    req = Request.blank("/")
++    assert req.get_response(res).location == "http://localhost/%2fwww.example.com/test"
++
++
+ @pytest.mark.xfail(sys.version_info < (3,0),
+                    reason="Python 2.x unicode != str, WSGI requires str. Test "
+                    "added due to https://github.com/Pylons/webob/issues/247. "
+-- 
+2.44.4
+
diff --git a/recipes-devtools/python/python3-webob_1.8.7.bb b/recipes-devtools/python/python3-webob_1.8.7.bb
index d23ddfd2..5d7f74c8 100644
--- a/recipes-devtools/python/python3-webob_1.8.7.bb
+++ b/recipes-devtools/python/python3-webob_1.8.7.bb
@@ -14,3 +14,5 @@ RDEPENDS:${PN} += " \
 	python3-sphinx \
 	"
 
+SRC_URI += "file://CVE-2024-42353.patch \
+           "
-- 
2.35.6



^ permalink raw reply related	[flat|nested] 4+ messages in thread

* [meta-virtualization][scarthgap][PATCH 2/2] python3-webob: fix CVE-2026-44889
  2026-08-06  5:54 [meta-virtualization][scarthgap][PATCH 1/2] python3-webob: fix CVE-2024-42353 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-08-06  5:54 ` Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
  2026-08-07 18:05   ` Bruce Ashfield
  2026-08-07 18:05 ` [meta-virtualization][scarthgap][PATCH 1/2] python3-webob: fix CVE-2024-42353 Bruce Ashfield
  1 sibling, 1 reply; 4+ messages in thread
From: Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-06  5:54 UTC (permalink / raw)
  To: meta-virtualization; +Cc: xe-linux-external, Darsh Kelaiya

From: Darsh Kelaiya <dkelaiya@cisco.com>

This patch applies the upstream fix as referenced in [2], using the
commit shown in [1].

[1] https://github.com/Pylons/webob/commit/21c1c582bff83dc6f95fdb055e31a36db6d26e89
[2] https://github.com/Pylons/webob/security/advisories/GHSA-fh3h-vg37-cc95

Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
---
 .../python/python3-webob/CVE-2026-44889.patch | 124 ++++++++++++++++++
 .../python/python3-webob_1.8.7.bb             |   1 +
 2 files changed, 125 insertions(+)
 create mode 100644 recipes-devtools/python/python3-webob/CVE-2026-44889.patch

diff --git a/recipes-devtools/python/python3-webob/CVE-2026-44889.patch b/recipes-devtools/python/python3-webob/CVE-2026-44889.patch
new file mode 100644
index 00000000..6100301d
--- /dev/null
+++ b/recipes-devtools/python/python3-webob/CVE-2026-44889.patch
@@ -0,0 +1,124 @@
+From 24a7763bdb5f391bb520d5b79ca0e5b13af7bbbe Mon Sep 17 00:00:00 2001
+From: Delta Regeer <xistence@0x58.com>
+Date: Wed, 6 May 2026 00:38:51 -0600
+Subject: [PATCH] Fix open redirect issue due to changes made in cPython >=3.10
+
+CVE: CVE-2026-44889
+Upstream-Status: Backport [https://github.com/Pylons/webob/commit/21c1c582bff83dc6f95fdb055e31a36db6d26e89]
+
+(cherry picked from commit 21c1c582bff83dc6f95fdb055e31a36db6d26e89)
+Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
+---
+ CHANGES.txt            | 15 ++++++++++++++
+ src/webob/response.py  | 11 +++++++---
+ tests/test_response.py | 46 ++++++++++++++++++++++++++++++++++++++++++
+ 3 files changed, 69 insertions(+), 3 deletions(-)
+
+diff --git a/CHANGES.txt b/CHANGES.txt
+index ca33450..056031f 100644
+--- a/CHANGES.txt
++++ b/CHANGES.txt
+@@ -1,3 +1,18 @@
++Unreleased
++----------
++
++Security Fix
++~~~~~~~~~~~~
++
++- The fix for CVE-2024-42353 was incomplete: a Location value containing
++  ASCII tab, carriage return, or line feed characters between consecutive
++  slashes could still be interpreted as a protocol-relative URL by
++  ``urllib.parse.urljoin`` on Python 3.10+, allowing an open redirect.
++
++  See https://github.com/Pylons/webob/security/advisories/GHSA-fh3h-vg37-cc95
++
++  Thanks to Caleb Brown of Google for the report.
++
+ 1.8.7 (2021-02-17)
+ ------------------
+ 
+diff --git a/src/webob/response.py b/src/webob/response.py
+index efc38ec..91b801c 100644
+--- a/src/webob/response.py
++++ b/src/webob/response.py
+@@ -1281,12 +1281,17 @@ class Response(object):
+ 
+     @staticmethod
+     def _make_location_absolute(environ, value):
++        # urllib.parse.urlsplit() (called internally by urljoin) strips
++        # ASCII tab, CR, and LF from the URL on Python 3.10+. Strip them
++        # ourselves first so they cannot be used to bypass the SCHEME_RE
++        # or protocol-relative ("//") checks below. See CVE-2024-42353,
++        # https://github.com/Pylons/webob/security/advisories/GHSA-mg3v-6m49-jhp3,
++        # and the follow-up advisory GHSA-fh3h-vg37-cc95.
++        value = value.replace("\t", "").replace("\r", "").replace("\n", "")
++
+         if SCHEME_RE.search(value):
+             return value
+ 
+-        # This is to fix an open redirect issue due to the way that
+-        # urlparse.urljoin works. See CVE-2024-42353 and
+-        # https://github.com/Pylons/webob/security/advisories/GHSA-mg3v-6m49-jhp3
+         if value.startswith("//"):
+             value = "/%2f{}".format(value[2:])
+         new_location = urlparse.urljoin(_request_uri(environ), value)
+diff --git a/tests/test_response.py b/tests/test_response.py
+index 8a6ac06..2cdd981 100644
+--- a/tests/test_response.py
++++ b/tests/test_response.py
+@@ -1042,6 +1042,52 @@ def test_location_no_open_redirect():
+     assert req.get_response(res).location == "http://localhost/%2fwww.example.com/test"
+ 
+ 
++@pytest.mark.parametrize("payload", [
++    "/\t/www.example.com/test",
++    "\t//www.example.com/test",
++    "//\twww.example.com/test",
++    "/\t\t/www.example.com/test",
++])
++def test_location_no_open_redirect_tab_bypass(payload):
++    # Follow-up to CVE-2024-42353. urllib.parse.urlsplit() (used internally
++    # by urljoin) strips ASCII tab on Python 3.10+, which allowed a
++    # Location value to bypass the "//" check and be parsed as
++    # protocol-relative. See GHSA-fh3h-vg37-cc95. (CR and LF are already
++    # rejected by the location header setter, so only tab is reachable
++    # via the public API.)
++    res = Response()
++    res.status = "301"
++    res.location = payload
++    req = Request.blank("/")
++    assert req.get_response(res).location == (
++        "http://localhost/%2fwww.example.com/test"
++    )
++
++
++@pytest.mark.parametrize("payload", [
++    "/\t/www.example.com/test",
++    "/\n/www.example.com/test",
++    "/\r/www.example.com/test",
++    "\t//www.example.com/test",
++    "\n//www.example.com/test",
++    "\r//www.example.com/test",
++    "//\twww.example.com/test",
++    "//\nwww.example.com/test",
++    "//\rwww.example.com/test",
++    "//\tw\nww.example.com/test",
++])
++def test__make_location_absolute_strips_url_whitespace(payload):
++    # Defense in depth for GHSA-fh3h-vg37-cc95: even when called with a
++    # Location value that bypasses the descriptor's CR/LF check (e.g. via
++    # direct manipulation of _headerlist), tab/CR/LF must not be usable to
++    # turn a relative path into a protocol-relative redirect.
++    result = Response._make_location_absolute(
++        {"wsgi.url_scheme": "http", "HTTP_HOST": "example.com:80"},
++        payload,
++    )
++    assert result == "http://example.com/%2fwww.example.com/test"
++
++
+ @pytest.mark.xfail(sys.version_info < (3,0),
+                    reason="Python 2.x unicode != str, WSGI requires str. Test "
+                    "added due to https://github.com/Pylons/webob/issues/247. "
+-- 
+2.35.6
+
diff --git a/recipes-devtools/python/python3-webob_1.8.7.bb b/recipes-devtools/python/python3-webob_1.8.7.bb
index 5d7f74c8..b5e40c06 100644
--- a/recipes-devtools/python/python3-webob_1.8.7.bb
+++ b/recipes-devtools/python/python3-webob_1.8.7.bb
@@ -15,4 +15,5 @@ RDEPENDS:${PN} += " \
 	"
 
 SRC_URI += "file://CVE-2024-42353.patch \
+            file://CVE-2026-44889.patch \
            "
-- 
2.35.6



^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [meta-virtualization][scarthgap][PATCH 1/2] python3-webob: fix CVE-2024-42353
  2026-08-06  5:54 [meta-virtualization][scarthgap][PATCH 1/2] python3-webob: fix CVE-2024-42353 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
  2026-08-06  5:54 ` [meta-virtualization][scarthgap][PATCH 2/2] python3-webob: fix CVE-2026-44889 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-08-07 18:05 ` Bruce Ashfield
  1 sibling, 0 replies; 4+ messages in thread
From: Bruce Ashfield @ 2026-08-07 18:05 UTC (permalink / raw)
  To: meta-virtualization

merged

Bruce


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [meta-virtualization][scarthgap][PATCH 2/2] python3-webob: fix CVE-2026-44889
  2026-08-06  5:54 ` [meta-virtualization][scarthgap][PATCH 2/2] python3-webob: fix CVE-2026-44889 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-08-07 18:05   ` Bruce Ashfield
  0 siblings, 0 replies; 4+ messages in thread
From: Bruce Ashfield @ 2026-08-07 18:05 UTC (permalink / raw)
  To: meta-virtualization

merged

Bruce


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-08-07 18:05 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-06  5:54 [meta-virtualization][scarthgap][PATCH 1/2] python3-webob: fix CVE-2024-42353 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-06  5:54 ` [meta-virtualization][scarthgap][PATCH 2/2] python3-webob: fix CVE-2026-44889 Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-08-07 18:05   ` Bruce Ashfield
2026-08-07 18:05 ` [meta-virtualization][scarthgap][PATCH 1/2] python3-webob: fix CVE-2024-42353 Bruce Ashfield

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.