PT-2021-22479 · Ifttt+1 · Ifttt+1
Rasmus Petersen
·
Published
2021-09-20
·
Updated
2021-10-04
·
CVE-2021-39229
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Apprise versions prior to 0.9.5.1
Description
The issue affects users of Apprise who have granted access to the IFTTT plugin, making them subject to a denial of service attack due to an inefficient regular expression. The vulnerable regular expression is located in the NotifyIFTTT.py file. This issue has been patched in release version 0.9.5.1.
Recommendations
For versions prior to 0.9.5.1, update to Apprise v0.9.5.1 by running
pip install apprise==0.9.5.1.
As a temporary workaround for users unable to upgrade, consider removing the apprise/plugins/NotifyIFTTT.py file to eliminate the vulnerable service, although this will disable IFTTT notification functionality.Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apprise
Ifttt