Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1ocmo3LWY2MmYtajd4N84AAvFK
rdiffweb allows unlimited length of root directory name, which could result in DoS
rdiffweb prior to 2.4.8 has no limit in length of root directory names. Allowing users to enter long strings may result in a DOS attack or memory corruption. Version 2.4.8 defines a field limit for username, email, and root directory.
Permalink: https://github.com/advisories/GHSA-hrj7-f62f-j7x7JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ocmo3LWY2MmYtajd4N84AAvFK
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 1 year ago
Updated: 8 months ago
CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Identifiers: GHSA-hrj7-f62f-j7x7, CVE-2022-3295
References:
- https://nvd.nist.gov/vuln/detail/CVE-2022-3295
- https://github.com/ikus060/rdiffweb/commit/667657c6fe2b336c90be37f37fb92f65df4feee3
- https://huntr.dev/bounties/202dd03a-3d97-4c64-bc73-1a0f36614233
- https://github.com/pypa/advisory-database/tree/main/vulns/rdiffweb/PYSEC-2022-293.yaml
- https://github.com/advisories/GHSA-hrj7-f62f-j7x7
Affected Packages
pypi:rdiffweb
Versions: >= 0, < 2.4.8Fixed in: 2.4.8