An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.
https://pypi.org/project/future/
https://github.com/PythonCharmers/python-future/pull/610
https://github.com/PythonCharmers/python-future/blob/master/src/future/backports/http/cookiejar.py#L215
Source: Mitre, NVD
Published: 2022-12-23
Updated: 2023-01-23
Base Score: 7.8
Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C
Severity: High
Base Score: 7.5
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H