CVE-2024-7592
Quadratic complexity parsing cookies with backslashes
7.5
HIGH
CVSS 3.1
EPSS 0.88%
Description
There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the cookie value, the parser would use an algorithm with quadratic complexity, resulting in excess CPU resources being used while parsing the value.
How to fix CVE-2024-7592
To remediate CVE-2024-7592, upgrade the affected package to a fixed version below.
- —upgrade to 3.10.15-r0 or later
- —upgrade to 3.8.20 or later
- —upgrade to 3.8.20 or later
- —upgrade to 3.8.20 or later
- —upgrade to 7.3.5+dfsg-2+deb11u5 or later
- —upgrade to 3.11.2-6+deb12u5 or later
- —upgrade to 3.13.0~rc2-1 or later
- —upgrade to 3.9.2-1+deb11u2 or later
Is CVE-2024-7592 being exploited?
Low — EPSS is 0.9%, meaning exploitation activity has not been observed at scale.
Affected packages (8)
- from 0, < 3.10.15-r0
- from 0, < 3.8.20, >= 3.9.0, < 3.9.20, >= 3.10.0, < 3.10.15, >= 3.11.0, < 3.11.10, >= 3.12.0, < 3.12.6
- from 0, < 3.8.20, >= 3.9.0, < 3.9.20, >= 3.10.0, < 3.10.15, >= 3.11.0, < 3.11.10, >= 3.12.0, < 3.12.6
- from 0, < 3.8.20, >= 3.9.0, < 3.9.20, >= 3.10.0, < 3.10.15, >= 3.11.0, < 3.11.10, >= 3.12.0, < 3.12.6
- from 0, < 7.3.5+dfsg-2+deb11u5
- from 0, < 3.11.2-6+deb12u5
- from 0, < 3.13.0~rc2-1
- from 0, < 3.9.2-1+deb11u2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |