Skip to content
This repository has been archived by the owner on Feb 8, 2024. It is now read-only.

CVE-2022-42969 (High) detected in py-1.10.0-py2.py3-none-any.whl #452

Closed
mend-for-github-com bot opened this issue Oct 17, 2022 · 1 comment
Closed
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource

Comments

@mend-for-github-com
Copy link

mend-for-github-com bot commented Oct 17, 2022

CVE-2022-42969 - High Severity Vulnerability

Vulnerable Library - py-1.10.0-py2.py3-none-any.whl

library with cross-python path, ini-parsing, io, code, log facilities

Library home page: https://files.pythonhosted.org/packages/67/32/6fe01cfc3d1a27c92fdbcdfc3f67856da8cbadf0dd9f2e18055202b2dc62/py-1.10.0-py2.py3-none-any.whl

Path to dependency file: /monitoring/ceph-mixin/tests_dashboards/requirements.txt

Path to vulnerable library: /monitoring/ceph-mixin/tests_dashboards/requirements.txt,/src/pybind/cephfs

Dependency Hierarchy:

  • py-1.10.0-py2.py3-none-any.whl (Vulnerable Library)

Found in HEAD commit: aa78617d024ccd26801e43c6980f939cf8bded5f

Found in base branch: main

Vulnerability Details

The py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data, because the InfoSvnCommand argument is mishandled.

Publish Date: 2022-10-16

URL: CVE-2022-42969

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

@mend-for-github-com mend-for-github-com bot added the Mend: dependency security vulnerability Security vulnerability detected by WhiteSource label Oct 17, 2022
@mend-for-github-com mend-for-github-com bot changed the title CVE-2022-42969 (Medium) detected in py-1.10.0-py2.py3-none-any.whl, py-1.11.0-py2.py3-none-any.whl CVE-2022-42969 (High) detected in py-1.10.0-py2.py3-none-any.whl, py-1.11.0-py2.py3-none-any.whl Nov 9, 2022
@mend-for-github-com mend-for-github-com bot changed the title CVE-2022-42969 (High) detected in py-1.10.0-py2.py3-none-any.whl, py-1.11.0-py2.py3-none-any.whl CVE-2022-42969 (High) detected in py-1.10.0-py2.py3-none-any.whl Nov 16, 2022
@shailesh-vaidya
Copy link

Closing as an obsolete

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource
Projects
None yet
Development

No branches or pull requests

1 participant