PT-2022-21561 · Rdiffweb · Rdiffweb

Published

2022-09-26

·

Updated

2022-09-28

·

CVE-2022-3290

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions rdiffweb versions prior to 2.4.8
Description The issue is related to improper handling of length parameter inconsistency. It can be exploited via an unlimited length username field, potentially leading to excess memory consumption or memory corruption, resulting in a Denial of Service (DoS).
Recommendations For versions prior to 2.4.8, update to version 2.4.8 to resolve the issue. As a temporary workaround, consider restricting the length of the username field to prevent potential exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-3290
GHSA-5V95-J4RR-6F3C
PYSEC-2022-292
PYSEC-2022-43184

Affected Products

Rdiffweb