Back
CVE-2017-0906
CRITICAL
The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource.get" method that could result in compromise of API keys or other critical resources.
Published: Nov 13, 2017
Modified: Jun 17, 2026
CWE-918
CWE-918
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (8)
| Vendor | Product | Version |
|---|---|---|
| recurly | recurly_client_python | * ≥ 2.0.0 |
| recurly | recurly_client_python | * ≥ 2.1.0 |
| recurly | recurly_client_python | * ≥ 2.2.0 |
| recurly | recurly_client_python | 2.3.0 |
| recurly | recurly_client_python | * ≥ 2.4.0 |
| recurly | recurly_client_python | 2.5.0 |
| recurly | recurly_client_python | 2.6.0 |
| recurly | recurly_client_python | 2.6.1 |
GitHub Security Advisory GHSA-38rv-5jqc-m2cv
Recurly vulnerable to SSRF
pip
recurly
>= 2.6.0, < 2.6.2
Fixed: 2.6.2
pip
recurly
= 2.5.0
Fixed: 2.5.1
pip
recurly
>= 2.4.0, < 2.4.5
Fixed: 2.4.5
pip
recurly
= 2.3.0
Fixed: 2.3.1
pip
recurly
>= 2.2.0, < 2.2.22
Fixed: 2.2.22
pip
recurly
>= 2.1.0, < 2.1.16
Fixed: 2.1.16
pip
recurly
< 2.0.5
Fixed: 2.0.5
References (6)
- https://dev.recurly.com/page/python-updates Vendor Advisory
- https://github.com/recurly/recurly-client-python/commit/049c74699ce93cf126feff06d632ea63fba36742 Patch, Third Party Advisory
- https://hackerone.com/reports/288635 Permissions Required
- https://dev.recurly.com/page/python-updates Vendor Advisory
- https://github.com/recurly/recurly-client-python/commit/049c74699ce93cf126feff06d632ea63fba36742 Patch, Third Party Advisory
- https://hackerone.com/reports/288635 Permissions Required
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
2.62%
Top 16% most likely to be exploited
Threat Score
40 / 100
Data Sources
NVD
EPSS
GitHub