{"id":"GHSA-rcrv-228c-gprj","aliases":[],"url":"https://o3.security/vulnerability/GHSA-rcrv-228c-gprj","summary":"Invalid URL generation in bitlyshortener","details":"### Impact\nDue to a sudden upstream breaking change by Bitly, versions of `bitlyshortener` <0.6.0 generate invalid short URLs. All users are affected and must update immediately.\n\n### Patches\nUpgrading `bitlyshortener` to 0.6.0 or newer will prevent the generation such invalid short URLs.\n\n### Workarounds\nA workaround is to replace \"https://j.mp/\" in each generated short URL with \"https://bit.ly/\".\n\n### References\n* [Release notes](https://github.com/impredicative/bitlyshortener/releases)","published":"2022-01-21T18:39:40Z","modified":"2024-12-04T05:42:18.698721Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"bitlyshortener","fixedVersion":"0.6.0"}],"fix":{"url":"https://github.com/impredicative/bitlyshortener/commit/b307d70bedf745305fa0dd3c5c600d8cb88d09b5","label":"impredicative/bitlyshortener@b307d70"},"references":[{"type":"WEB","url":"https://github.com/impredicative/bitlyshortener/security/advisories/GHSA-rcrv-228c-gprj"},{"type":"WEB","url":"https://github.com/impredicative/bitlyshortener/commit/b307d70bedf745305fa0dd3c5c600d8cb88d09b5"},{"type":"PACKAGE","url":"https://github.com/impredicative/bitlyshortener"},{"type":"WEB","url":"https://github.com/impredicative/bitlyshortener/releases/tag/0.6.0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-04T05:42:18.698721Z"}}