Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h3q4-6j7f-r24c

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 6.6
CVSS3: 7.5

Описание

priority vulnerable to denial of service

A HTTP/2 implementation built using any version of the Python priority library prior to version 1.2.0 could be targeted by a malicious peer by having that peer assign priority information for every possible HTTP/2 stream ID. The priority tree would happily continue to store the priority information for each stream, and would therefore allocate unbounded amounts of memory. Attempting to actually use a tree like this would also cause extremely high CPU usage to maintain the tree.

Пакеты

Наименование

priority

pip
Затронутые версииВерсия исправления

< 1.2.0

1.2.0

EPSS

Процентиль: 64%
0.00476
Низкий

6.6 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
nvd
около 9 лет назад

A HTTP/2 implementation built using any version of the Python priority library prior to version 1.2.0 could be targeted by a malicious peer by having that peer assign priority information for every possible HTTP/2 stream ID. The priority tree would happily continue to store the priority information for each stream, and would therefore allocate unbounded amounts of memory. Attempting to actually use a tree like this would also cause extremely high CPU usage to maintain the tree.

CVSS3: 7.5
fstec
около 9 лет назад

Уязвимость библиотеки python priority library, связанная с ошибками управления ресурсами, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 64%
0.00476
Низкий

6.6 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-770