Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-40897
HistoryDec 23, 2022 - 12:15 a.m.

Denial of service

2022-12-2300:15:00
PRIOn knowledge base
www.prio-n.com
10
pypa setuptools
denial of service
html
crafted package
packageindex
regular expression denial of service
redos

5.7 Medium

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

77.5%

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.

CPENameOperatorVersion
setuptoolslt65.5.1