First published: Fri Sep 30 2022(Updated: )
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Ikus-soft Rdiffweb | <=2.4.9 | |
Ikus-soft Rdiffweb | =2.5.0-alpha1 | |
Ikus-soft Rdiffweb | =2.5.0-alpha2 | |
pip/rdiffweb | <2.5.0a3 | 2.5.0a3 |
<=2.4.9 | ||
=2.5.0-alpha1 | ||
=2.5.0-alpha2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-3371 is high with a CVSS score of 7.5.
CVE-2022-3371 affects Ikus-soft Rdiffweb software versions up to 2.4.9 and versions 2.5.0-alpha1 and 2.5.0-alpha2.
CVE-2022-3371 is an allocation of resources without limits or throttling vulnerability in GitHub repository ikus060/rdiffweb prior to version 2.5.0a3.
To fix CVE-2022-3371, update Ikus-soft Rdiffweb to version 2.5.0a3 or later.
Yes, you can find more information about CVE-2022-3371 at the following links: [Link 1](https://github.com/ikus060/rdiffweb/commit/b62c479ff6979563c7c23e7182942bc4f460a2c7) and [Link 2](https://huntr.dev/bounties/4e8f6136-50c7-4fa1-ac98-699bcb7b35ce).