Lucene search

K
redosRedosROS-20230428-01
HistoryApr 28, 2023 - 12:00 a.m.

ROS-20230428-01

2023-04-2800:00:00
redos.red-soft.ru
8
python charmers future
input validation
set-cookie header
remote exploitation
denial of service
regular expressions
unix

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.004 Low

EPSS

Percentile

74.4%

A vulnerability in the Python Charmers Future program is related to improper input validation when processing the
the Set-Cookie header. Exploitation of the vulnerability could allow an attacker acting remotely to
to send a specially crafted HTTP request to the application and perform a denial of service (ReDoS) attack using the Python Charmers Future program
(ReDoS) attack using regular expressions.

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64python3-future<= 0.18.3-1UNKNOWN

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.004 Low

EPSS

Percentile

74.4%