Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-30798

Опубликовано: 21 апр. 2023
Источник: debian

Описание

There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify any number of form fields or files which can cause excessive memory usage resulting in denial of service of the HTTP service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
starlettefixed0.25.0-1package
starletteno-dsabullseyepackage

Примечания

  • https://github.com/encode/starlette/commit/8c74c2c8dba7030154f8af18e016136bea1938fa (0.25.0)

  • https://github.com/encode/starlette/security/advisories/GHSA-74m5-2c7w-9w3x

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify any number of form fields or files which can cause excessive memory usage resulting in denial of service of the HTTP service.

CVSS3: 7.5
nvd
почти 3 года назад

There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify any number of form fields or files which can cause excessive memory usage resulting in denial of service of the HTTP service.

CVSS3: 7.5
github
почти 3 года назад

MultipartParser denial of service with too many fields or files