BIT-python-min-2024-7592

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/python-min/BIT-python-min-2024-7592.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-python-min-2024-7592
Aliases
Published
2025-01-17T15:05:21.600Z
Modified
2025-01-17T17:44:11.988788Z
Summary
[none]
Details

There is a LOW severity vulnerability affecting CPython, specifically the'http.cookies' standard library module.When parsing cookies that contained backslashes for quoted characters inthe cookie value, the parser would use an algorithm with quadraticcomplexity, resulting in excess CPU resources being used while parsing thevalue.

Database specific
{
    "cpes": [
        "cpe:2.3:a:python:python:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / python-min

Package

Name
python-min
Purl
pkg:bitnami/python-min

Severity

  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
3.12.0
Fixed
3.12.6
Introduced
3.11.0
Fixed
3.11.10
Introduced
3.10.0
Fixed
3.10.15
Introduced
3.9.0
Fixed
3.9.20
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.8.20