Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7pmh-vrww-25xx

Опубликовано: 30 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 2.4
CVSS3: 2.8

Описание

freewvs's nested directory structure can interrupt scan

Impact

A directory structure of more than 1000 nested directories can interrupt a freewvs scan due to Python's recursion limit and os.walk(). This can be problematic in a case where an administrator scans the dirs of potentially untrusted users.

Patches

This has been fixed in this commit by limiting the recursion to 500 directories: https://github.com/schokokeksorg/freewvs/commit/83a6b55c0435c69f447488b791555e6078803143

This issue was discovered by Hanno Böck.

Пакеты

Наименование

freewvs

pip
Затронутые версииВерсия исправления

< 0.1.1

0.1.1

EPSS

Процентиль: 39%
0.00174
Низкий

2.4 Low

CVSS4

2.8 Low

CVSS3

Дефекты

CWE-674

Связанные уязвимости

CVSS3: 2.8
nvd
больше 5 лет назад

In freewvs before 0.1.1, a directory structure of more than 1000 nested directories can interrupt a freewvs scan due to Python's recursion limit and os.walk(). This can be problematic in a case where an administrator scans the dirs of potentially untrusted users. This has been patched in 0.1.1.

EPSS

Процентиль: 39%
0.00174
Низкий

2.4 Low

CVSS4

2.8 Low

CVSS3

Дефекты

CWE-674