CVE-2022-40897
pypa-setuptools: Regular Expression Denial of Service (ReDoS) in package_index.py
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.
Las herramientas de configuración Python Packaging Authority (PyPA) anteriores a 65.5.1 permiten a atacantes remotos provocar una Denegación de Servicio (DoS) a través de HTML en un paquete manipulado o en una página PackageIndex personalizada. Hay una Denegación de Servicio (DoS) de expresión regular (ReDoS) en package_index.py.
A flaw was found in Python Setuptools due to a regular expression Denial of Service (ReDoS) present in package_index.py. This issue could allow a remote attacker to cause a denial of service via HTML in a crafted package or custom PackageIndex page.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2022-09-19 CVE Reserved
- 2022-12-22 CVE Published
- 2024-07-14 EPSS Updated
- 2024-10-29 CVE Updated
- 2024-10-29 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-185: Incorrect Regular Expression
- CWE-1333: Inefficient Regular Expression Complexity
CAPEC
References (11)
URL | Date | SRC |
---|---|---|
https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages | 2024-10-29 |
URL | Date | SRC |
---|---|---|
https://github.com/pypa/setuptools/commit/43a9c9bfa6aa626ec2a22540bea28d2ca77964be | 2024-06-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Python Search vendor "Python" | Setuptools Search vendor "Python" for product "Setuptools" | < 65.5.1 Search vendor "Python" for product "Setuptools" and version " < 65.5.1" | - |
Affected
|