CVE-2021-3733 — Uncontrolled Resource Consumption in Redhat Enterprise Linux Server AUS
Severity
6.5MEDIUMNVD
EPSS
0.8%
top 26.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 10
Latest updateJul 11
Description
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6
Affected Packages4 packages
Also affects: Fedora 33, 34, 35, 36, Enterprise Linux 8.0, 8.4
Patches
🔴Vulnerability Details
6📋Vendor Advisories
7Microsoft▶
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to could trigger a Regular Expression Den↗2022-03-08