Описание
There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify any number of form fields or files which can cause excessive memory usage resulting in denial of service of the HTTP service.
Ссылки
- Patch
- MitigationVendor Advisory
- PatchThird Party Advisory
- Patch
- MitigationVendor Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.25.0 (исключая)
cpe:2.3:a:encode:starlette:*:*:*:*:*:python:*:*
EPSS
Процентиль: 74%
0.00827
Низкий
7.5 High
CVSS3
Дефекты
CWE-400
CWE-400
Связанные уязвимости
CVSS3: 7.5
ubuntu
почти 3 года назад
There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify any number of form fields or files which can cause excessive memory usage resulting in denial of service of the HTTP service.
CVSS3: 7.5
debian
почти 3 года назад
There MultipartParser usage in Encode's Starlette python framework bef ...
CVSS3: 7.5
github
почти 3 года назад
MultipartParser denial of service with too many fields or files
EPSS
Процентиль: 74%
0.00827
Низкий
7.5 High
CVSS3
Дефекты
CWE-400
CWE-400