pympp is vulnerable to Origin Validation Error
68
Medium Risk
The PaymentTransport in pympp does not verify that a 402 Payment Required challenge comes from the origin of the initially requested URL. When redirect following is enabled, a redirect can send the request to a different scheme, host, or port and the transport still generates and sends payment authorization credentials to that new origin. This lets a redirect destination receive payment credentials that were intended for the original site. The fix records the original request origin and rejects payment challenges produced by origin-changing redirects before any credentials are created.
You are affected if you are using a version that falls within the vulnerable range and you have enabled redirect following on a client that uses PaymentTransport.
pympp is vulnerable to Origin Validation Error in versions 0.0.1 - 0.10.0.
Upgrade the pympp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.