Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hr7v-m862-8hh8

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.

EPSS

Процентиль: 38%
0.00162
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-835

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.

CVSS3: 6.5
redhat
больше 4 лет назад

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.

CVSS3: 7.5
nvd
почти 4 года назад

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.

CVSS3: 7.5
msrc
почти 4 года назад

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker who controls the HTTP server to make the client script enter an infinite loop consuming CPU time. The highest threat from this vulnerability is to system availability.

CVSS3: 7.5
debian
почти 4 года назад

A flaw was found in python. An improperly handled HTTP response in the ...

EPSS

Процентиль: 38%
0.00162
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-835