You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Path to dependency file: /docs/sphinx_requirements.txt
Path to vulnerable library: /docs/sphinx_requirements.txt,/requirements.txt,/docs/sphinx_requirements.txt,/tmp/ws-scm/face,/PRNet-master/requirements.txt
Path to dependency file: /docs/sphinx_requirements.txt
Path to vulnerable library: /docs/sphinx_requirements.txt,/requirements.txt,/docs/sphinx_requirements.txt,/tmp/ws-scm/face,/PRNet-master/requirements.txt
A Denial of Service (DoS) vulnerability exists in the jaraco/zipp library, affecting all versions prior to 3.19.1. The vulnerability is triggered when processing a specially crafted zip file that leads to an infinite loop. This issue also impacts the zipfile module of CPython, as features from the third-party zipp library are later merged into CPython, and the affected code is identical in both projects. The infinite loop can be initiated through the use of functions affecting the Path module in both zipp and zipfile, such as joinpath, the overloaded division operator, and iterdir. Although the infinite loop is not resource exhaustive, it prevents the application from responding. The vulnerability was addressed in version 3.19.1 of jaraco/zipp.
Micro-Learning Topic: Denial of service (Detected by phrase)
Matched on "Denial of Service"
The Denial of Service (DoS) attack is focused on making a resource (site, application, server) unavailable for the purpose it was designed. There are many ways to make a service unavailable for legitimate users by manipulating network packets, programming, logical, or resources handling vulnerabilities, among others. Source: https://www.owasp.org/index.php/Denial_of_Service
Use of vulnerable components will introduce weaknesses into the application. Components with published vulnerabilities will allow easy exploitation as resources will often be available to automate the process.
mend-bolt-for-githubbot
changed the title
zipp-3.15.0-py3-none-any.whl: 1 vulnerabilities (highest severity is: 3.3)
zipp-3.15.0-py3-none-any.whl: 1 vulnerabilities (highest severity is: 6.2)
Jul 31, 2024
mend-bolt-for-githubbot
changed the title
zipp-3.15.0-py3-none-any.whl: 1 vulnerabilities (highest severity is: 6.2)
zipp-3.15.0-py3-none-any.whl: 1 vulnerabilities (highest severity is: 3.3)
Aug 1, 2024
Backport of pathlib-compatible object wrapper for zip files
Library home page: https://files.pythonhosted.org/packages/5b/fa/c9e82bbe1af6266adf08afb563905eb87cab83fde00a0a08963510621047/zipp-3.15.0-py3-none-any.whl
Path to dependency file: /docs/sphinx_requirements.txt
Path to vulnerable library: /docs/sphinx_requirements.txt,/requirements.txt,/docs/sphinx_requirements.txt,/tmp/ws-scm/face,/PRNet-master/requirements.txt
Found in HEAD commit: 1def381581db59d139b24ef0a32eed6f8e3b2af8
Vulnerabilities
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - zipp-3.15.0-py3-none-any.whl
Backport of pathlib-compatible object wrapper for zip files
Library home page: https://files.pythonhosted.org/packages/5b/fa/c9e82bbe1af6266adf08afb563905eb87cab83fde00a0a08963510621047/zipp-3.15.0-py3-none-any.whl
Path to dependency file: /docs/sphinx_requirements.txt
Path to vulnerable library: /docs/sphinx_requirements.txt,/requirements.txt,/docs/sphinx_requirements.txt,/tmp/ws-scm/face,/PRNet-master/requirements.txt
Dependency Hierarchy:
Found in HEAD commit: 1def381581db59d139b24ef0a32eed6f8e3b2af8
Found in base branch: master
Vulnerability Details
A Denial of Service (DoS) vulnerability exists in the jaraco/zipp library, affecting all versions prior to 3.19.1. The vulnerability is triggered when processing a specially crafted zip file that leads to an infinite loop. This issue also impacts the zipfile module of CPython, as features from the third-party zipp library are later merged into CPython, and the affected code is identical in both projects. The infinite loop can be initiated through the use of functions affecting the
Path
module in both zipp and zipfile, such asjoinpath
, the overloaded division operator, anditerdir
. Although the infinite loop is not resource exhaustive, it prevents the application from responding. The vulnerability was addressed in version 3.19.1 of jaraco/zipp.Publish Date: 2024-07-09
URL: CVE-2024-5569
CVSS 3 Score Details (3.3)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://huntr.com/bounties/be898306-11f9-46b4-b28c-f4c4aa4ffbae
Release Date: 2024-07-09
Fix Resolution: 3.19.1
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: