Описание
copyparty allows Regex Denial of Service (ReDoS) in the upload listing
Summary
The filter parameter for the "Recent uploads" page allows arbitrary Regexes. If this feature is enabled (which is the default), an attacker can craft a filter which deadlocks the server.
PoC
https://127.0.0.1:3923/?ru&filter=(.+)+x
Impact
The server becomes fully inaccessible for a long time.
Пакеты
Наименование
copyparty
pip
Затронутые версииВерсия исправления
<= 1.18.8
1.18.9
Связанные уязвимости
CVSS3: 7.5
nvd
6 месяцев назад
Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this feature is enabled (which is the default), an attacker can craft a filter which deadlocks the server. This is fixed in version 1.18.9.