Safety vulnerability ID: 51457
The information on this page was manually curated by our Cybersecurity Intelligence Team.
** DISPUTED ** Py throughout 1.11.0 allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data because the InfoSvnCommand argument is mishandled.
https://github.com/pytest-dev/py/issues/287
Latest version: 1.11.0
library with cross-python path, ini-parsing, io, code, log facilities
The py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data, because the InfoSvnCommand argument is mishandled. See CVE-2022-42969.
MISC:https://github.com/pytest-dev/py/blob/cb87a83960523a2367d0f19226a73aed4ce4291d/py/_path/svnurl.py#L316: https://github.com/pytest-dev/py/blob/cb87a83960523a2367d0f19226a73aed4ce4291d/py/_path/svnurl.py#L316
MISC:https://github.com/pytest-dev/py/issues/287: https://github.com/pytest-dev/py/issues/287
MISC:https://pypi.org/project/py: https://pypi.org/project/py
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application