CVE Vulnerabilities

CVE-2022-40898

Published: Dec 23, 2022 | Modified: Dec 30, 2022
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.

Affected Software

Name Vendor Start Version End Version
Wheel Wheel_project * 0.38.1 (excluding)
Red Hat Enterprise Linux 9 RedHat python-wheel-1:0.36.2-8.el9 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-python38-python-wheel-0:0.33.6-9.el7 *
Python-pip Ubuntu bionic *
Python-pip Ubuntu devel *
Python-pip Ubuntu esm-apps/xenial *
Python-pip Ubuntu focal *
Python-pip Ubuntu jammy *
Python-pip Ubuntu kinetic *
Python-pip Ubuntu trusty *
Python-pip Ubuntu trusty/esm *
Python-pip Ubuntu upstream *
Python-pip Ubuntu xenial *
Wheel Ubuntu bionic *
Wheel Ubuntu devel *
Wheel Ubuntu esm-apps/xenial *
Wheel Ubuntu focal *
Wheel Ubuntu jammy *
Wheel Ubuntu kinetic *
Wheel Ubuntu trusty *
Wheel Ubuntu trusty/esm *
Wheel Ubuntu upstream *
Wheel Ubuntu xenial *

References