Skip to content
This repository has been archived by the owner on Dec 17, 2022. It is now read-only.

Update bitlyshortener to >=0.6.0 to prevent generating invalid short URLs

Critical
impredicative published GHSA-rcrv-228c-gprj Jan 19, 2022

Package

pip bitlyshortener (pip)

Affected versions

<0.6.0

Patched versions

0.6.0

Description

Impact

Due to a sudden upstream breaking change by Bitly, versions of bitlyshortener <0.6.0 generate invalid short URLs. All users are affected and must update immediately.

Patches

Upgrading bitlyshortener to 0.6.0 or newer will prevent the generation such invalid short URLs.

Workarounds

A workaround is to replace "https://j.mp/" in each generated short URL with "https://bit.ly/".

References

Severity

Critical

CVE ID

No known CVE

Weaknesses

No CWEs