Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-7592

Опубликовано: 19 авг. 2024
Источник: redhat
CVSS3: 4.8

Описание

There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the cookie value, the parser would use an algorithm with quadratic complexity, resulting in excess CPU resources being used while parsing the value.

A flaw was found in the http.cookies module in the Python package. When parsing cookies that contain backslashes, under certain circumstances, the module uses an algorithm with quadratic complexity, leading to excessive CPU consumption.

Отчет

This vulnerability is classified as low severity, as also marked by upstream Python, because while it can cause excessive CPU usage, its exploitability is constrained by practical factors. Most production environments enforce request size limits (e.g., via web servers like Nginx or Apache), preventing attackers from sending arbitrarily large cookies. Additionally, the impact is localized to individual requests, meaning it does not persistently degrade system performance or lead to remote code execution (RCE). The attack requires multiple large requests to have a significant effect, making it inefficient compared to more severe denial-of-service (DoS) vectors.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6pythonFix deferred
Red Hat Enterprise Linux 7pythonFix deferred
Red Hat Enterprise Linux 7python3Fix deferred
Red Hat Enterprise Linux 8gimp:flatpak/python2Fix deferred
Red Hat Enterprise Linux 8python3Fix deferred
Red Hat Enterprise Linux 8python3.11Fix deferred
Red Hat Enterprise Linux 8python3.12Fix deferred
Red Hat Enterprise Linux 8python36:3.6/python36Fix deferred
Red Hat Enterprise Linux 8python39:3.9/python39Fix deferred
Red Hat Enterprise Linux 8python39-devel:3.9/python39Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2305879cpython: python: Uncontrolled CPU resource consumption when in http.cookies module

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
10 месяцев назад

There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the cookie value, the parser would use an algorithm with quadratic complexity, resulting in excess CPU resources being used while parsing the value.

CVSS3: 7.5
nvd
10 месяцев назад

There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the cookie value, the parser would use an algorithm with quadratic complexity, resulting in excess CPU resources being used while parsing the value.

CVSS3: 7.5
msrc
8 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
10 месяцев назад

There is a LOW severity vulnerability affecting CPython, specifically ...

CVSS3: 7.5
redos
8 месяцев назад

Уязвимость python3.12

4.8 Medium

CVSS3