py: ReDoS in py library when used with subversion
Published Oct 16, 2022
7.5
HIGHCVSS 3.1
EPSS 1.67%
Description
The py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data, because the InfoSvnCommand argument is mishandled. Note: This has been disputed by multiple third parties as not being reproduceable and they argue this is not a valid vulnerability.
Affected products
No data.
No data.
Red Hat OpenShift Container Platform 4
ose-aws-efs-utils-container
Fix deferred
Service Telemetry Framework 1.5
stf/prometheus-webhook-snmp-rhel8
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | ose-aws-efs-utils-container | Fix deferred | n/a |
| Service Telemetry Framework 1.5 | stf/prometheus-webhook-snmp-rhel8 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This has been disputed by multiple parties, including the upstream maintainers, as not being reproducible or a valid vulnerability.
References (9)
- https://access.redhat.com/security/cve/CVE-2022-42969 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2312846 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-0207 Advisory
- https://github.com/pytest-dev/py/blob/cb87a83960523a2367d0f19226a73aed4ce4291d/py/_path/svnurl.py#L316 Product
- https://github.com/pytest-dev/py/issues/287 ExploitIssue TrackingThird Party Advisory
- https://news.ycombinator.com/item?id=34163710 Issue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-42969
- https://pypi.org/project/py Product
- https://www.cve.org/CVERecord?id=CVE-2022-42969
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-42969 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2312846 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-0207 | Advisory | |
| https://github.com/pytest-dev/py/blob/cb87a83960523a2367d0f19226a73aed4ce4291d/py/_path/svnurl.py#L316 | Product | |
| https://github.com/pytest-dev/py/issues/287 | ExploitIssue TrackingThird Party Advisory | |
| https://news.ycombinator.com/item?id=34163710 | Issue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-42969 | ||
| https://pypi.org/project/py | Product | |
| https://www.cve.org/CVERecord?id=CVE-2022-42969 |
Change history (0)
No recorded changes yet.