Resource Exhaustion
Affecting python3.7 package, versions <3.7.3-2+deb10u2
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.
References
CVSS Score
6.5
medium severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2020-8492
- CWE
- CWE-400
- Snyk ID
- SNYK-DEBIAN10-PYTHON37-543814
- Disclosed
- 30 Jan, 2020
- Published
- 30 Jan, 2020