Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2024-7592

Description

There is a LOW severity vulnerability affecting CPython, specifically the'http.cookies' standard library module.When parsing cookies that contained backslashes for quoted characters inthe cookie value, the parser would use an algorithm with quadraticcomplexity, resulting in excess CPU resources being used while parsing thevalue.

POC

Reference

No PoCs from references.

Github

- https://github.com/GitHubForSnap/matrix-commander-gael

- https://github.com/adegoodyer/kubernetes-admin-toolkit

- https://github.com/ch4n3-yoon/ch4n3-yoon

- https://github.com/fkie-cad/nvd-json-data-feeds

- https://github.com/robertsirc/sle-bci-demo