CVE-2017-18361: High severity colander vulnerability
In Pylons Colander through 1.6, the URL validator allows an attacker to potentially cause an infinite loop thereby causing a denial of service via an unclosed parenthesis.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18361?
The severity of CVE-2017-18361 is high with a CVSS score of 7.5.
How does CVE-2017-18361 affect Pylons Colander?
CVE-2017-18361 affects Pylons Colander versions up to and including 1.6.
What is the impact of CVE-2017-18361?
CVE-2017-18361 can potentially cause an infinite loop, leading to a denial of service.
How can I fix the vulnerability in Pylons Colander?
To fix the vulnerability, upgrade Pylons Colander to version 1.7.0 or later.
Where can I find more information about CVE-2017-18361?
You can find more information about CVE-2017-18361 at the following references: - [NIST National Vulnerability Database](https://nvd.nist.gov/vuln/detail/CVE-2017-18361) - [GitHub Issue](https://github.com/Pylons/colander/issues/290) - [GitHub Pull Request](https://github.com/Pylons/colander/pull/323)