Описание
snowflake-connector-python is vulnerable to Regular Expression Denial of Service (ReDoS)
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the snowflake-connector-python PyPI package, when an attacker is able to supply arbitrary input to the get_file_transfer_type method.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2022-42965
- https://github.com/snowflakedb/snowflake-connector-python/pull/1327
- https://github.com/snowflakedb/snowflake-connector-python/commit/b9d2fc789fae4db865dde3d2a1bd72c8a9eab091
- https://github.com/snowflakedb/snowflake-connector-python/releases/tag/v2.8.2
- https://research.jfrog.com/vulnerabilities/snowflake-connector-python-redos-xray-257185
Пакеты
Наименование
snowflake-connector-python
pip
Затронутые версииВерсия исправления
< 2.8.2
2.8.2
Связанные уязвимости
CVSS3: 3.7
nvd
почти 4 года назад
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the snowflake-connector-python PyPI package, when an attacker is able to supply arbitrary input to the undocumented get_file_transfer_type method