Incorrect Regular Expression in Python Charmers Future - CVE-2022-40899

 

Incorrect Regular Expression in Python Charmers Future - CVE-2022-40899

Published: January 12, 2023


Vulnerability identifier: #VU71137
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-40899
CWE-ID: CWE-185
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation when processing the Set-Cookie header. A remote attacker can send a specially crafted HTTP request to the application and perform a regular expression denial of service (ReDoS) attack.


Affected software

Python Charmers Future
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
EMC ECS
APEX Cloud Platform for Microsoft Azure
PowerStore T
IBM Cloud Pak for Watson AIOps
Storage Resource Manager
Amazon Linux AMI
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Web Scripting
Web and Scripting Module
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 12 SP4 ESPOS
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
openSUSE Leap
Ubuntu
openEuler
IBM Cloud Pak for Multicloud Management
HPE Moonshot 1500 Chassis Manager
Python for Scientific Computing
Red Hat Satellite
Spectrum Discover
APEX Cloud Platform for Red Hat OpenShift
Red Hat Update Infrastructure (RHUI)
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Splunk Enterprise
python3-future (Ubuntu package)
python-future (Ubuntu package)
rubygem-hammer_cli_foreman_ansible (Red Hat package)
python-future
future
python3-future
python2-future
python-future (Red Hat package)
rubygem-foreman_maintain (Red Hat package)
rubygem-safemode (Red Hat package)
python3-base-debuginfo
libpython3_4m1_0-debuginfo-32bit
python3-base-debugsource
python3-dbm
python3-dbm-debuginfo
python3-debuginfo
python3-debugsource
python3-devel
python3-devel-debuginfo
libpython3_4m1_0
libpython3_4m1_0-debuginfo
python3
python3-base
python3-curses
python3-curses-debuginfo
python3-tk
python3-tk-debuginfo
libpython3_4m1_0-32bit
python3-base-debuginfo-32bit
foreman (Red Hat package)
rubygem-fog-vsphere (Red Hat package)
python-pulp-rpm (Red Hat package)
python-pulpcore (Red Hat package)
rubygem-katello (Red Hat package)
satellite (Red Hat package)
rubygem-foreman_ansible (Red Hat package)
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)

How to mitigate CVE-2022-40899

Install updates from vendor's website.

Python Charmers Future - update to 0.18.3
IBM Cloud Pak for Multicloud Management - update to 2.3.8
EMC ECS - update to 3.7.0.6
Python for Scientific Computing - update to 4.2.1
Red Hat Satellite - addressed in versions 6.13.3, 6.14
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.0.8, 9.0.9, 9.1.1, 9.1.3, 9.1.4, 9.2.1
python3-future (Ubuntu package) - addressed in versions Ubuntu Pro, 0.15.2-4ubuntu2.1, 0.18.2-2ubuntu0.1, 0.18.2-5ubuntu0.1, 0.18.2-6ubuntu0.1
python-future (Ubuntu package) - addressed in versions Ubuntu Pro, 0.15.2-4ubuntu2.1
rubygem-hammer_cli_foreman_ansible (Red Hat package) - update to 0.5.0-1.el8sat
python-future - addressed in versions 0.15.2-3.3.1, 0.15.2-3.5.1
future - update to 0.16.0-12
python3-future - update to 0.16.0-12
python2-future - update to 0.16.0-12
python3-future - update to 0.18.2-150300.3.3.1
future - update to 0.18.3-1
python-future (Red Hat package) - update to 0.18.3-1.el8pc
rubygem-foreman_maintain (Red Hat package) - update to 1.2.11-1.el8sat
rubygem-safemode (Red Hat package) - update to 1.3.8-1.el8sat
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
APEX Cloud Platform for Red Hat OpenShift - update to 03.04.01.00
python3-base-debuginfo - addressed in versions 3.4.10-25.105.1, 3.4.10-25.108.1
libpython3_4m1_0-debuginfo-32bit - addressed in versions 3.4.10-25.105.1, 3.4.10-25.108.1
python3-base-debugsource - addressed in versions 3.4.10-25.105.1, 3.4.10-25.108.1
python3-dbm - addressed in versions 3.4.10-25.105.1, 3.4.10-25.108.1
python3-dbm-debuginfo - addressed in versions 3.4.10-25.105.1, 3.4.10-25.108.1
python3-debuginfo - addressed in versions 3.4.10-25.105.1, 3.4.10-25.108.1
python3-debugsource - addressed in versions 3.4.10-25.105.1, 3.4.10-25.108.1
python3-devel - addressed in versions 3.4.10-25.105.1, 3.4.10-25.108.1
python3-devel-debuginfo - addressed in versions 3.4.10-25.105.1, 3.4.10-25.108.1
libpython3_4m1_0 - addressed in versions 3.4.10-25.105.1, 3.4.10-25.108.1
libpython3_4m1_0-debuginfo - addressed in versions 3.4.10-25.105.1, 3.4.10-25.108.1
python3 - addressed in versions 3.4.10-25.105.1, 3.4.10-25.108.1
python3-base - addressed in versions 3.4.10-25.105.1, 3.4.10-25.108.1
python3-curses - addressed in versions 3.4.10-25.105.1, 3.4.10-25.108.1
python3-curses-debuginfo - addressed in versions 3.4.10-25.105.1, 3.4.10-25.108.1
python3-tk - addressed in versions 3.4.10-25.105.1, 3.4.10-25.108.1
python3-tk-debuginfo - addressed in versions 3.4.10-25.105.1, 3.4.10-25.108.1
libpython3_4m1_0-32bit - addressed in versions 3.4.10-25.105.1, 3.4.10-25.108.1
python3-base-debuginfo-32bit - addressed in versions 3.4.10-25.105.1, 3.4.10-25.108.1
PowerStore T - update to 3.5.0.1-2083289
foreman (Red Hat package) - update to 3.5.1.19-1.el8sat
rubygem-fog-vsphere (Red Hat package) - update to 3.6.2-1.el8sat
python-pulp-rpm (Red Hat package) - update to 3.18.17-1.el8pc
python-pulpcore (Red Hat package) - update to 3.21.9-1.el8pc
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
IBM Cloud Pak for Watson AIOps - update to 4.1
Red Hat Update Infrastructure (RHUI) - update to 4.4.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.4
rubygem-katello (Red Hat package) - update to 4.7.0.31-1.el8sat
EMC ViPR SRM - update to 4.9.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - addressed in versions 4.9.0.0, 5.0.2.2
Storage Resource Manager - update to 5.0.2.2
satellite (Red Hat package) - update to 6.13.3-1.el8sat
rubygem-foreman_ansible (Red Hat package) - update to 10.4.3-1.el8sat

External References

Related Security Bulletins