Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rwqr-c348-m5wr

Опубликовано: 24 июн. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

Withdrawn: Denial of Service in aiohttp

Withdrawn

This advisory has been withdrawn because the maintainers of aiohttp and multiple third parties disputed the validity of the issue. There is not sufficient evidence for the claims in the original report.

Original Description

aiohttp v3.8.1 was discovered to contain an invalid IPv6 URL which can lead to a Denial of Service (DoS).

Пакеты

Наименование

aiohttp

pip
Затронутые версииВерсия исправления

<= 3.8.1

Отсутствует

EPSS

Процентиль: 48%
0.00252
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

AIOHTTP 3.8.1 can report a "ValueError: Invalid IPv6 URL" outcome, which can lead to a Denial of Service (DoS). NOTE: multiple third parties dispute this issue because there is no example of a context in which denial of service would occur, and many common contexts have exception handing in the calling application

redhat
больше 3 лет назад

AIOHTTP 3.8.1 can report a "ValueError: Invalid IPv6 URL" outcome, which can lead to a Denial of Service (DoS). NOTE: multiple third parties dispute this issue because there is no example of a context in which denial of service would occur, and many common contexts have exception handing in the calling application

CVSS3: 5.5
nvd
больше 3 лет назад

AIOHTTP 3.8.1 can report a "ValueError: Invalid IPv6 URL" outcome, which can lead to a Denial of Service (DoS). NOTE: multiple third parties dispute this issue because there is no example of a context in which denial of service would occur, and many common contexts have exception handing in the calling application

CVSS3: 5.5
debian
больше 3 лет назад

AIOHTTP 3.8.1 can report a "ValueError: Invalid IPv6 URL" outcome, whi ...

EPSS

Процентиль: 48%
0.00252
Низкий

5.5 Medium

CVSS3