First published: Thu Dec 22 2022(Updated: )
An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wheel Project Wheel | <0.38.1 | |
pip/wheel | <0.38.1 | 0.38.1 |
redhat/python-wheel | <0.38.0 | 0.38.0 |
IBM Data Virtualization on Cloud Pak for Data | <=3.0 | |
IBM Watson Query with Cloud Pak for Data as a Service | <=2.2 | |
IBM Watson Query with Cloud Pak for Data as a Service | <=2.1 | |
IBM Watson Query with Cloud Pak for Data as a Service | <=2.0 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.8 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40898 is classified as a denial of service vulnerability affecting specific versions of the Wheel package.
To fix CVE-2022-40898, upgrade to Wheel version 0.38.1 or later.
CVE-2022-40898 affects Wheel versions 0.37.1 and earlier.
Yes, CVE-2022-40898 can be exploited remotely by attackers to induce a denial of service.
CVE-2022-40898 impacts various IBM products including Data Virtualization and Watson Query when using affected versions of the Wheel package.