GHSA-2p9h-ccw7-33gf

Source
https://github.com/advisories/GHSA-2p9h-ccw7-33gf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-2p9h-ccw7-33gf/GHSA-2p9h-ccw7-33gf.json
Aliases
  • CVE-2022-42966
Published
2022-11-10T12:01:17Z
Modified
2023-11-08T04:10:40.813474Z
Details

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the cleo PyPI package, when an attacker is able to supply arbitrary input to the Table.set_rows method.

References

Affected packages

PyPI / cleo

Package

Name
cleo

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
1.0.0

Affected versions

0.*

0.2.0
0.2.1
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4b1
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1

1.*

1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5

Ecosystem specific

{
    "affected_functions": [
        "cleo.ui.table.Table._render_cell"
    ]
}

Database specific

{
    "last_known_affected_version_range": "<= 1.0.0a5"
}