Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qwmp-2cf2-g9g6

Опубликовано: 23 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

pypa/wheel vulnerable to Regular Expression denial of service (ReDoS)

Python Packaging Authority (PyPA) Wheel is a reference implementation of the Python wheel packaging standard. Wheel 0.37.1 and earlier are vulnerable to a Regular Expression denial of service via attacker controlled input to the wheel cli. The vulnerable regex is used to verify the validity of Wheel file names. This has been patched in version 0.38.1.

Пакеты

Наименование

wheel

pip
Затронутые версииВерсия исправления

< 0.38.1

0.38.1

EPSS

Процентиль: 42%
0.00196
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.

CVSS3: 7.5
redhat
больше 2 лет назад

An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.

CVSS3: 7.5
nvd
больше 2 лет назад

An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.

CVSS3: 7.5
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
больше 2 лет назад

An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 ...

EPSS

Процентиль: 42%
0.00196
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333