Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.
References
Configurations
History
No history.
Information
Published : 2022-12-23 00:15
Updated : 2024-11-21 07:22
NVD link : CVE-2022-40897
Mitre link : CVE-2022-40897
CVE.ORG link : CVE-2022-40897
JSON object : View
Products Affected
python
- setuptools
CWE
CWE-1333
Inefficient Regular Expression Complexity