Уязвимость DoS атаки через регулярное выражение в классе "AbstractBasicAuthHandler" библиотеки "urllib"
Описание
Существует уязвимость в классе AbstractBasicAuthHandler
библиотеки urllib
. Злоумышленник, который контролирует вредоносный HTTP-сервер, к которому подключается HTTP-клиент (например, веб-браузер), способен вызвать DoS атаку через регулярное выражение (ReDOS) во время аутентификационного запроса с помощью специально сформированного пакета, отправленного сервером клиенту. Основная угроза, которую представляет эта уязвимость, заключается в нарушении доступности приложения.
Тип уязвимости
- ReDOS (DoS атака через регулярное выражение)
- Нарушение доступности приложения
Ссылки
- ExploitIssue TrackingPatchVendor Advisory
- Issue TrackingThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- ExploitIssue TrackingPatchVendor Advisory
- Issue TrackingThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Одно из
Одно из
Одно из
Одно из
EPSS
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
Связанные уязвимости
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker ...
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.
EPSS
6.5 Medium
CVSS3
4 Medium
CVSS2