jnunemaker / httparty

:tada: Makes http fun again!
MIT License
5.81k stars 964 forks source link

Is GHSA-5pq7-52mg-hr42 remotely exploitable? #785

Open ag-TJNII opened 1 year ago

ag-TJNII commented 1 year ago

I'm reading https://github.com/advisories/GHSA-5pq7-52mg-hr42 and I'm not quite following the attack vector. If I'm reading it properly this vulnerability requires malicious local input to HTTParty? Is there a vulnerability here triggerable by a HTTP response?