Description: An issue in the urllib.parse component of Python before v3.11 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters. Broken commit info: Bugfix commit info: https://github.com/python/cpython/pull/99421 https://github.com/python/cpython/pull/99421 https://github.com/python/cpython/pull/99421 https://github.com/python/cpython/pull/99421 https://github.com/python/cpython/pull/99446 (backport for 3.11 branch)
anolis 23 中的python版本是3.10.12,已经修复该漏洞。 https://docs.python.org/release/3.10.12/whatsnew/changelog.html#python-3-10-12-final