Skip to content

Commit

Permalink
Browse files Browse the repository at this point in the history
  • Loading branch information
webknjaz committed Jun 26, 2022
1 parent 81d730b commit eb52378
Showing 1 changed file with 12 additions and 5 deletions.
Original file line number Diff line number Diff line change
@@ -1,13 +1,13 @@
{
"schema_version": "1.2.0",
"id": "GHSA-rwqr-c348-m5wr",
"modified": "2022-06-25T07:22:37Z",
"modified": "2022-06-26T19:16:55Z",
"published": "2022-06-24T00:00:31Z",
"aliases": [
"CVE-2022-33124"
],
"summary": "Denial of Service in aiohttp",
"details": "aiohttp v3.8.1 was discovered to contain an invalid IPv6 URL which can lead to a Denial of Service (DoS).",
"summary": "Not a real problem: Denial of Service in aiohttp",
"details": "> aiohttp v3.8.1 was discovered to contain an invalid IPv6 URL which can lead to a Denial of Service (DoS).\n\nThis claim seems to be invalid: it links to a missing explanation on what the reporter actually means. As an aiohttp maintainer, I see _zero_ proof of any of this being a problem. Also, nobody contacted us to report a vulnerability.\n\nCurrent recommendation: treat this \"report\" as nonsense.\n\n-- @webknjaz",
"severity": [

],
Expand All @@ -23,12 +23,15 @@
"events": [
{
"introduced": "0"
},
{
"fixed": ">= 0"
}
]
}
],
"database_specific": {
"last_known_affected_version_range": "<= 3.8.1"
"last_known_affected_version_range": "< 0"
}
}
],
Expand All @@ -41,6 +44,10 @@
"type": "WEB",
"url": "https://github.com/aio-libs/aiohttp/issues/6772"
},
{
"type": "WEB",
"url": "https://github.com/aio-libs/aiohttp/issues/6801#issuecomment-1166620200"
},
{
"type": "PACKAGE",
"url": "https://github.com/aio-libs/aiohttp"
Expand All @@ -50,7 +57,7 @@
"cwe_ids": [

],
"severity": "MODERATE",
"severity": "LOW",
"github_reviewed": true
}
}

0 comments on commit eb52378

Please sign in to comment.