python-aiohttp: invalid IPv6 URL which can lead to a Denial of Service with exception raised
Published Jun 22, 2022
5.5
MEDIUMCVSS 3.1
EPSS 0.72%
Description
AIOHTTP 3.8.1 can report a "ValueError: Invalid IPv6 URL" outcome, which can lead to a Denial of Service (DoS). NOTE: multiple third parties dispute this issue because there is no example of a context in which denial of service would occur, and many common contexts have exception handing in the calling application
Affected products
No data.
No data.
Red Hat Ansible Automation Platform 1.2
aiohttp
Not affected
Red Hat Ansible Automation Platform 1.2
python-aiohttp
Not affected
Red Hat Ansible Automation Platform 2
python-aiohttp
Not affected
Red Hat Ansible Tower 3
aiohttp
Not affected
Red Hat Satellite 6
python-aiohttp
Not affected
Red Hat Update Infrastructure 4 for Cloud Providers
python-aiohttp
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Automation Platform 1.2 | aiohttp | Not affected | n/a |
| Red Hat Ansible Automation Platform 1.2 | python-aiohttp | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | python-aiohttp | Not affected | n/a |
| Red Hat Ansible Tower 3 | aiohttp | Not affected | n/a |
| Red Hat Satellite 6 | python-aiohttp | Not affected | n/a |
| Red Hat Update Infrastructure 4 for Cloud Providers | python-aiohttp | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security does not consider this to be a vulnerability.
References (6)
- https://access.redhat.com/security/cve/CVE-2022-33124 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2103107 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-0002 Advisory
- https://github.com/aio-libs/aiohttp/issues/6772 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-33124
- https://www.cve.org/CVERecord?id=CVE-2022-33124
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-33124 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2103107 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-0002 | Advisory | |
| https://github.com/aio-libs/aiohttp/issues/6772 | x_refsource_MISCExploitIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-33124 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-33124 |
Change history (0)
No recorded changes yet.