PT-2022-21604 · Rdiffweb · Rdiffweb

Published

2022-09-26

·

Updated

2022-09-28

·

CVE-2022-3295

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions rdiffweb versions prior to 2.4.8
Description The issue concerns the allocation of resources without limits or throttling, which can lead to a denial-of-service (DOS) attack or memory corruption. Specifically, there is no limit on the length of root directory names, allowing users to enter long strings. This can be exploited to cause a DOS attack or memory corruption.
Recommendations For versions prior to 2.4.8, update to version 2.4.8, which defines field limits for username, email, and root directory to prevent this issue.

Exploit

Fix

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2022-3295
GHSA-HRJ7-F62F-J7X7
PYSEC-2022-293

Affected Products

Rdiffweb