PT-2021-22479 · Ifttt+1 · Ifttt+1

Rasmus Petersen

·

Published

2021-09-20

·

Updated

2021-10-04

·

CVE-2021-39229

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apprise versions prior to 0.9.5.1
Description The issue affects users of Apprise who have granted access to the IFTTT plugin, making them subject to a denial of service attack due to an inefficient regular expression. The vulnerable regular expression is located in the NotifyIFTTT.py file. This issue has been patched in release version 0.9.5.1.
Recommendations For versions prior to 0.9.5.1, update to Apprise v0.9.5.1 by running pip install apprise==0.9.5.1. As a temporary workaround for users unable to upgrade, consider removing the apprise/plugins/NotifyIFTTT.py file to eliminate the vulnerable service, although this will disable IFTTT notification functionality.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-39229
GHSA-QHMP-H54X-38QR
PYSEC-2021-327

Affected Products

Apprise
Ifttt