Bug 2165866 (CVE-2022-40899)

Summary: CVE-2022-40899 python-future: remote attackers can cause denial of service via crafted Set-Cookie header from malicious web server
Product: [Other] Security Response Reporter: Dhananjay Arunesh <darunesh>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: akarol, apevec, bbuckingham, bcoca, bcourt, btotty, cwelton, davidn, dfreiber, dmetzger, eglynn, ehelms, epacific, gmccullo, gtanzill, jburrell, jcammara, jhardy, jjoyce, jneedle, jobarker, jsherril, lhh, lzap, mabashia, mburns, mgarciac, mhulan, mminar, nmoumoul, orabin, osapryki, pcreech, python-maint, rbiba, rchan, rhos-maint, rogbas, roliveri, rtillery, simaishi, smallamp, smcdonal, spower, sskracic, teagle, vkumar, yguenane, zsadeh
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A denial of service flaw was found in Python Charmers Future. This flaw allows an attacker to send a specially crafted Set-Cookie header in an HTTP request, resulting in a loss of system availability.
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-05-03 21:12:58 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2166186, 2166187, 2166188, 2166681, 2168176, 2168177, 2168178, 2168179, 2218955    
Bug Blocks: 2165868    

Description Dhananjay Arunesh 2023-01-31 10:15:56 UTC
An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.

References:
https://pypi.org/project/future/
https://github.com/python/cpython/pull/17157
https://github.com/PythonCharmers/python-future/blob/master/src/future/backports/http/cookiejar.py#L215
https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/

Comment 6 errata-xmlrpc 2023-05-03 14:55:58 UTC
This issue has been addressed in the following products:

  RHUI 4 for RHEL 8

Via RHSA-2023:2101 https://access.redhat.com/errata/RHSA-2023:2101

Comment 7 Product Security DevOps Team 2023-05-03 21:12:54 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2022-40899

Comment 9 errata-xmlrpc 2023-08-03 13:30:16 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.13 for RHEL 8

Via RHSA-2023:4466 https://access.redhat.com/errata/RHSA-2023:4466

Comment 10 errata-xmlrpc 2023-11-08 14:17:16 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.14 for RHEL 8

Via RHSA-2023:6818 https://access.redhat.com/errata/RHSA-2023:6818