Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4r6j-fwcx-94cf

Опубликовано: 10 нояб. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

snowflake-connector-python is vulnerable to Regular Expression Denial of Service (ReDoS)

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the snowflake-connector-python PyPI package, when an attacker is able to supply arbitrary input to the get_file_transfer_type method.

Пакеты

Наименование

snowflake-connector-python

pip
Затронутые версииВерсия исправления

< 2.8.2

2.8.2

EPSS

Процентиль: 57%
0.00862
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 3.7
nvd
почти 4 года назад

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the snowflake-connector-python PyPI package, when an attacker is able to supply arbitrary input to the undocumented get_file_transfer_type method

EPSS

Процентиль: 57%
0.00862
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-1333