Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-40897

Опубликовано: 22 дек. 2022
Источник: redhat
CVSS3: 5.9

Описание

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.

A flaw was found in Python Setuptools due to a regular expression Denial of Service (ReDoS) present in package_index.py. This issue could allow a remote attacker to cause a denial of service via HTML in a crafted package or custom PackageIndex page.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2python-setuptoolsNot affected
Red Hat Enterprise Linux 6python-setuptoolsOut of support scope
Red Hat Enterprise Linux 7python3-setuptoolsOut of support scope
Red Hat Enterprise Linux 7python-setuptoolsOut of support scope
Red Hat Enterprise Linux 8python3.11-setuptoolsNot affected
Red Hat Enterprise Linux 9python3.11-setuptoolsNot affected
Red Hat OpenShift Container Platform 4python-setuptoolsNot affected
Red Hat OpenShift Dev Spacespython-setuptoolsNot affected
Red Hat OpenStack Platform 16.1python-setuptoolsWill not fix
Red Hat Quay 3python-setuptoolsAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-185
https://bugzilla.redhat.com/show_bug.cgi?id=2158559pypa-setuptools: Regular Expression Denial of Service (ReDoS) in package_index.py

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 2 лет назад

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.

CVSS3: 5.9
nvd
больше 2 лет назад

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.

CVSS3: 5.9
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 5.9
debian
больше 2 лет назад

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remo ...

suse-cvrf
больше 1 года назад

Security update for python3-setuptools

5.9 Medium

CVSS3