Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2022-40897

Description

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.

POC

Reference

- https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/

Github

- https://github.com/ARPSyndicate/cvemon

- https://github.com/Anna-Rafaella/Conteneurisation

- https://github.com/Atamik03/API-calc-dz

- https://github.com/CKA-codespace/cg-compare

- https://github.com/Dariani223/DevOpsFinal

- https://github.com/Fred090821/devops

- https://github.com/Fred090821/devopsdocker

- https://github.com/GadziorWTH/zadanie1

- https://github.com/GitHubForSnap/matrix-commander-gael

- https://github.com/Jidendiran-coder/trivy-grafana-alert-system

- https://github.com/JuhLima89/Exercicios

- https://github.com/Lennoxgonz/Docker-Container-Security-Hardening

- https://github.com/OzNetNerd/CheckovOutputProcessor

- https://github.com/SCH227/own-research

- https://github.com/SenhorDosSonhos1/projeto-voluntario-lacrei

- https://github.com/Sirelfer/base-project

- https://github.com/Viselabs/zammad-google-cloud-docker

- https://github.com/XXRadeonXFX/flask-vuln-app

- https://github.com/XXRadeonXFX/trivy-grafana-ai-alert-automation

- https://github.com/bygregonline/devsec-fastapi-report

- https://github.com/efrei-ADDA84/20200511

- https://github.com/equinixmetal-buildkite/trivy-buildkite-plugin

- https://github.com/fetter-io/fetter-py

- https://github.com/fetter-io/fetter-rs

- https://github.com/fredrkl/trivy-demo

- https://github.com/jbugeja/test-repo

- https://github.com/mansi1811-s/samp

- https://github.com/rjmfernandes/cp-connect-custom-image

- https://github.com/seal-community/patches

- https://github.com/thirumalai-py/trivy-grafana-ai-alert