Описание
Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions from 3.0.0rc1 to before 3.26.2 and from 4.0.0 to before 4.1.2, Schema.load(data, many=True) is vulnerable to denial of service attacks. A moderately sized request can consume a disproportionate amount of CPU time. This issue has been patched in version 3.26.2 and 4.1.2.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needed | |
| esm-apps/bionic | not-affected | code not present |
| esm-apps/focal | released | 3.4.0-1ubuntu0.1~esm1 |
| esm-apps/jammy | released | 3.13.0-1ubuntu0.1~esm1 |
| esm-apps/noble | released | 3.20.1-1.1ubuntu0.1~esm1 |
| esm-apps/resolute | released | 3.26.1-0.4ubuntu0.1~esm1 |
| jammy | needed | |
| noble | needed | |
| plucky | ignored | end of life, was needs-triage |
| questing | ignored | end of life, was needed |
Показывать по
Ссылки на источники
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions from 3.0.0rc1 to before 3.26.2 and from 4.0.0 to before 4.1.2, Schema.load(data, many=True) is vulnerable to denial of service attacks. A moderately sized request can consume a disproportionate amount of CPU time. This issue has been patched in version 3.26.2 and 4.1.2.
Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions from 3.0.0rc1 to before 3.26.2 and from 4.0.0 to before 4.1.2, Schema.load(data, many=True) is vulnerable to denial of service attacks. A moderately sized request can consume a disproportionate amount of CPU time. This issue has been patched in version 3.26.2 and 4.1.2.
Marshmallow is a lightweight library for converting complex objects to ...
EPSS
5.3 Medium
CVSS3