Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r9hx-vwmv-q579

Опубликовано: 23 дек. 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)

Python Packaging Authority (PyPA)'s setuptools is a library designed to facilitate packaging Python projects. Setuptools version 65.5.0 and earlier could allow remote attackers to cause a denial of service by fetching malicious HTML from a PyPI package or custom PackageIndex page due to a vulnerable Regular Expression in package_index. This has been patched in version 65.5.1.

Пакеты

Наименование

setuptools

pip
Затронутые версииВерсия исправления

< 65.5.1

65.5.1

EPSS

Процентиль: 54%
0.00318
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 2 лет назад

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.

CVSS3: 5.9
redhat
больше 2 лет назад

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.

CVSS3: 5.9
nvd
больше 2 лет назад

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.

CVSS3: 5.9
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 5.9
debian
больше 2 лет назад

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remo ...

EPSS

Процентиль: 54%
0.00318
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-1333