{"id":"GHSA-r82c-j4mq-5xfw","aliases":[],"url":"https://o3.security/vulnerability/GHSA-r82c-j4mq-5xfw","summary":"Update bitlyshortener to >=0.5.0 to prevent generating some invalid short URLs","details":"### Impact\nDue to a sudden upstream breaking change by Bitly, versions of `bitlyshortener` <0.5.0 can generate an invalid short URL when a vanity domain exists.\n\n### Patches\nUpgrading `bitlyshortener` to 0.5.0 or newer will prevent the generation of any such invalid short URLs.\n\n### References\n* [Release notes](https://github.com/impredicative/bitlyshortener/releases)","published":"2020-10-27T19:19:56Z","modified":"2024-12-02T05:51:37.842631Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"bitlyshortener","fixedVersion":"0.5.0"}],"fix":{"url":"https://github.com/impredicative/bitlyshortener/commit/3d412feb77f3daf6f71536463734c2119a55968d","label":"impredicative/bitlyshortener@3d412fe"},"references":[{"type":"WEB","url":"https://github.com/impredicative/bitlyshortener/security/advisories/GHSA-r82c-j4mq-5xfw"},{"type":"WEB","url":"https://github.com/impredicative/bitlyshortener/commit/3d412feb77f3daf6f71536463734c2119a55968d"},{"type":"WEB","url":"https://github.com/impredicative/bitlyshortener/releases/tag/0.5.0"},{"type":"WEB","url":"https://pypi.org/project/bitlyshortener"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:51:37.842631Z"}}