First published: Thu Sep 29 2022(Updated: )
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Ikus-soft Rdiffweb | <=2.4.9 | |
Ikus-soft Rdiffweb | =2.5.0-alpha1 | |
Ikus-soft Rdiffweb | =2.5.0-alpha2 | |
pip/rdiffweb | <2.5.0a3 | 2.5.0a3 |
<=2.4.9 | ||
=2.5.0-alpha1 | ||
=2.5.0-alpha2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3364 is a vulnerability that allows the allocation of resources without limits or throttling in the GitHub repository ikus060/rdiffweb prior to version 2.5.0a3.
CVE-2022-3364 has a severity rating of 7.5 out of 10, which is considered high.
The Ikus-soft Rdiffweb GitHub repository versions up to and including 2.4.9, 2.5.0-alpha1, and 2.5.0-alpha2 are affected by CVE-2022-3364.
To fix CVE-2022-3364, it is recommended to update the affected Ikus-soft Rdiffweb GitHub repository to version 2.5.0a3 or newer.
You can find more information about CVE-2022-3364 in the following references: [GitHub commit](https://github.com/ikus060/rdiffweb/commit/b62c479ff6979563c7c23e7182942bc4f460a2c7) and [Huntr.dev bounty](https://huntr.dev/bounties/e70ad507-1424-463b-bdf1-c4a6fbe6e720).