Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 PyPI

rdiffweb allows unlimited length of root directory name, which could result in DoS

GHSA-hrj7-f62f-j7x7 · CVE-2022-3295 · PYSEC-2022-293

Published · Modified

Description

rdiffweb prior to 2.4.8 has no limit in length of root directory names. Allowing users to enter long strings may result in a DOS attack or memory corruption. Version 2.4.8 defines a field limit for username, email, and root directory.

Ready to move

Start Securing

Free, no credit card | First findings in minutes