Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 PyPI

rdiffweb vulnerable to potential DoS via memory consumption

GHSA-xhw9-4wqq-x67v · CVE-2022-3298 · PYSEC-2022-294

Published · Modified

Description

rdiffweb prior to 2.4.8 is vulnerable to a potential Dos attack via an unlimited length "title" field when adding an SSH key.
This can result in excess memory consumption, leading to a Denial of Service (DoS). This issue is patched in version 2.4.8. There are no known workarounds.

Ready to move

Start Securing

Free, no credit card | First findings in minutes