CVE-2021-3733

⚪ Do wiadomości

Błąd w klasie AbstractBasicAuthHandler w urllib może prowadzić do odmowy usługi przez atak ReDOS.

CVSS
6.5
EPSS
4.7%
Exploit
poc
Vendor
redhat
Opis źródłowy (NVD)

There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.

dos exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)4.7%
Opublikowano (NVD)2022-03-10 17:42:59 UTC
Ostatnia modyfikacja (NVD)2026-10-08 21:17:41 UTC
Referencje