CVE-2023-45813
Summary
| CVE | CVE-2023-45813 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-18 21:15:00 UTC |
| Updated | 2023-10-30 13:37:00 UTC |
| Description | Torbot is an open source tor network intelligence tool. In affected versions the `torbot.modules.validators.validate_link function` uses the python-validators URL validation regex. This particular regular expression has an exponential complexity which allows an attacker to cause an application crash using a well-crafted argument. An attacker can use a well-crafted URL argument to exploit the vulnerability in the regular expression and cause a Denial of Service on the system. The validators file has been removed in version 4.0.0. Users are advised to upgrade. There are no known workarounds for this vulnerability. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Inefficient Regular Expression Complexity in validate_link · Advisory · DedSecInside/TorBot · GitHub |
MISC |
github.com |
|
| remove unused validators file · DedSecInside/TorBot@ef6e06b · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995663 Python (Pip) Security Update for torbot (GHSA-72qw-p7hh-m3ff)