PT-2022-26685 · Pypi · Cleo

Denys Vozniuk

·

Published

2022-11-09

·

Updated

2023-07-06

·

CVE-2022-42966

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions cleo (affected versions not specified)
Description An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the cleo PyPI package when an attacker is able to supply arbitrary input to the Table.set rows method.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Weakness Enumeration

Related Identifiers

CVE-2022-42966
GHSA-2P9H-CCW7-33GF
PYSEC-2022-43178

Affected Products

Cleo