PT-2023-29703 · Unknown+1 · Python-Validators+1

Ikkebr

·

Published

2023-10-18

·

Updated

2023-10-30

·

CVE-2023-45813

CVSS v3.1

4.6

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Torbot versions prior to 4.0.0
Description The issue concerns the torbot.modules.validators.validate link function, which uses the python-validators URL validation regex. This regular expression has exponential complexity, allowing an attacker to cause an application crash using a well-crafted argument. An attacker can exploit the vulnerability in the regular expression using a well-crafted URL argument, causing a Denial of Service on the system.
Recommendations For versions prior to 4.0.0, users are advised to upgrade to version 4.0.0 or later, as the validators file has been removed in this version, resolving the issue. As a temporary workaround, consider disabling the torbot.modules.validators.validate link function until a patch is available.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2023-45813
GHSA-72QW-P7HH-M3FF

Affected Products

Torbot
Python-Validators