This repository has been archived by the owner on Feb 8, 2024. It is now read-only.
CVE-2022-42969 (High) detected in py-1.10.0-py2.py3-none-any.whl #452
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2022-42969 - High Severity Vulnerability
Vulnerable Library - py-1.10.0-py2.py3-none-any.whl
library with cross-python path, ini-parsing, io, code, log facilities
Library home page: https://files.pythonhosted.org/packages/67/32/6fe01cfc3d1a27c92fdbcdfc3f67856da8cbadf0dd9f2e18055202b2dc62/py-1.10.0-py2.py3-none-any.whl
Path to dependency file: /monitoring/ceph-mixin/tests_dashboards/requirements.txt
Path to vulnerable library: /monitoring/ceph-mixin/tests_dashboards/requirements.txt,/src/pybind/cephfs
Dependency Hierarchy:
Found in HEAD commit: aa78617d024ccd26801e43c6980f939cf8bded5f
Found in base branch: main
Vulnerability Details
The py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data, because the InfoSvnCommand argument is mishandled.
Publish Date: 2022-10-16
URL: CVE-2022-42969
CVSS 3 Score Details (7.5)
Base Score Metrics:
The text was updated successfully, but these errors were encountered: