cve/2022/CVE-2022-40897.md

28 lines
1.2 KiB
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2022-40897](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40897)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.
### POC
#### Reference
- https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/Fred090821/devops
- https://github.com/Fred090821/devopsdocker
- https://github.com/GitHubForSnap/matrix-commander-gael
- https://github.com/SenhorDosSonhos1/projeto-voluntario-lacrei
- https://github.com/Viselabs/zammad-google-cloud-docker
- https://github.com/efrei-ADDA84/20200511
- https://github.com/fredrkl/trivy-demo
- https://github.com/jbugeja/test-repo
- https://github.com/mansi1811-s/samp
- https://github.com/seal-community/patches