Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-40899

Опубликовано: 21 дек. 2022
Источник: redhat
CVSS3: 7.5

Описание

An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.

A denial of service flaw was found in Python Charmers Future. This flaw allows an attacker to send a specially crafted Set-Cookie header in an HTTP request, resulting in a loss of system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5python-futureOut of support scope
Red Hat Ansible Automation Platform 2python-futureNot affected
Red Hat Enterprise Linux 7python-futuresWill not fix
Red Hat OpenShift Container Platform 3.11python-futuresOut of support scope
Red Hat OpenShift Container Platform 4futureAffected
Red Hat OpenStack Platform 13 (Queens)futureOut of support scope
Red Hat OpenStack Platform 13 (Queens)python-futuresOut of support scope
Red Hat OpenStack Platform 16.1futureWill not fix
Red Hat OpenStack Platform 16.2futureNot affected
Red Hat OpenStack Platform 17.0futureNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2165866python-future: remote attackers can cause denial of service via crafted Set-Cookie header from malicious web server

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.

CVSS3: 7.5
nvd
больше 2 лет назад

An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.

CVSS3: 7.5
debian
больше 2 лет назад

An issue discovered in Python Charmers Future 0.18.2 and earlier allow ...

suse-cvrf
больше 2 лет назад

Security update for python-future

suse-cvrf
больше 2 лет назад

Security update for python-future

7.5 High

CVSS3