Asymmetric denial of service - ReDoS In python3
Description
Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
alpine v3.11 | 3.8.2-r0 | ||
alpine v3.13 | 3.8.2-r0 | ||
alpine v3.18 | 3.8.2-r0 | ||
alpine v3.22 | 3.8.2-r0 | ||
alpine v3.21 | 3.8.2-r0 | ||
alpine v3.10 | 3.7.7-r0 | ||
alpine v3.15 | 3.8.2-r0 | ||
alpine v3.17 | 3.8.2-r0 | ||
alpine v3.19 | 3.8.2-r0 | ||
alpine v3.20 | 3.8.2-r0 |
1-10 of 24
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15.
References
1. 2. 3. 4. 5. 6. 7. 8.