Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2p9h-ccw7-33gf

Опубликовано: 10 нояб. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

cleo is vulnerable to Regular Expression Denial of Service (ReDoS)

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the cleo PyPI package, when an attacker is able to supply arbitrary input to the Table.set_rows method.

Пакеты

Наименование

cleo

pip
Затронутые версииВерсия исправления

< 2.0.0

2.0.0

EPSS

Процентиль: 32%
0.00124
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 3 лет назад

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the cleo PyPI package, when an attacker is able to supply arbitrary input to the Table.set_rows method

CVSS3: 5.9
nvd
около 3 лет назад

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the cleo PyPI package, when an attacker is able to supply arbitrary input to the Table.set_rows method

CVSS3: 5.9
debian
около 3 лет назад

An exponential ReDoS (Regular Expression Denial of Service) can be tri ...

EPSS

Процентиль: 32%
0.00124
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-1333