Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.
History

Tue, 29 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Aus
Redhat rhel E4s
Redhat rhel Tus
CPEs cpe:/a:redhat:rhel_aus:8.6
cpe:/a:redhat:rhel_e4s:8.6
cpe:/a:redhat:rhel_tus:8.6
Vendors & Products Redhat rhel Aus
Redhat rhel E4s
Redhat rhel Tus

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-12-22T00:00:00

Updated: 2024-10-29T14:55:11.665Z

Reserved: 2022-09-19T00:00:00

Link: CVE-2022-40897

cve-icon Vulnrichment

Updated: 2024-08-03T12:28:42.612Z

cve-icon NVD

Status : Modified

Published: 2022-12-23T00:15:13.987

Modified: 2024-11-21T07:22:13.787

Link: CVE-2022-40897

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-12-22T00:00:00Z

Links: CVE-2022-40897 - Bugzilla