The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource.get" method that could result in compromise of API keys or other critical resources.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| recurly(PyPI) | 2.6.0 | 2.6.2 | N/A |
| recurly(PyPI) | 2.5.0 | 2.5.1 | N/A |
| recurly(PyPI) | 2.4.0 | 2.4.5 | N/A |
| recurly(PyPI) | 2.3.0 | 2.3.1 | N/A |
| recurly(PyPI) | 2.2.0 | 2.2.22 | N/A |
| recurly(PyPI) | 2.1.0 | 2.1.16 | N/A |
| recurly(PyPI) | 0 | 2.0.5 | N/A |
CVSS Metrics