You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Mar 11, 2024. It is now read-only.
Repository navigation
This repository was archived by the owner on Mar 11, 2024. It is now read-only.
CVE-2022-40899 (High) detected in future-0.18.2.tar.gz #42
Path to vulnerable library: /requirements.txt,/tmp/ws-scm/kalel
Dependency Hierarchy:
❌ future-0.18.2.tar.gz (Vulnerable Library)
Found in base branch: master
Vulnerability Details
An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.
changed the title [-]CVE-2022-40899 (Medium) detected in future-0.18.2.tar.gz[/-][+]CVE-2022-40899 (High) detected in future-0.18.2.tar.gz[/+]on Jan 6, 2023
CVE-2022-40899 - High Severity Vulnerability
Clean single-source support for Python 3 and 2
Library home page: https://files.pythonhosted.org/packages/45/0b/38b06fd9b92dc2b68d58b75f900e97884c45bedd2ff83203d933cf5851c9/future-0.18.2.tar.gz
Path to dependency file: /requirements.txt
Path to vulnerable library: /requirements.txt,/tmp/ws-scm/kalel
Dependency Hierarchy:
Found in base branch: master
An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.
Publish Date: 2022-12-23
URL: CVE-2022-40899
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Step up your Open Source Security Game with Mend here