Fedora 39 : python-fastapi / python-starlette (2023-6c030b3c71)

high Nessus Plugin ID 194578

Language:

Synopsis

The remote Fedora host is missing one or more security updates.

Description

The remote Fedora 39 host has packages installed that are affected by a vulnerability as referenced in the FEDORA-2023-6c030b3c71 advisory.

- ## `python-starlette` 0.25.0 ### Fixed - Limit the number of fields and files when parsing `multipart/form-data` on the `MultipartParser` ## `python-fastapi` 0.92.0 This is a security fix.
Please upgrade as soon as possible. ### Upgrades * Upgrade Starlette to 0.25.0. * This solves a vulnerability that could allow denial of service attacks by using many small multipart fields/files (parts), consuming high CPU and memory. * Only applications using forms (e.g. file uploads) could be affected. * For most cases, upgrading won't have any breaking changes. (FEDORA-2023-6c030b3c71)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected python-fastapi and / or python-starlette packages.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2023-6c030b3c71

Plugin Details

Severity: High

ID: 194578

File Name: fedora_2023-6c030b3c71.nasl

Version: 1.0

Type: local

Agent: unix

Published: 4/29/2024

Updated: 4/29/2024

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Vulnerability Information

CPE: cpe:/o:fedoraproject:fedora:39, p-cpe:/a:fedoraproject:fedora:python-fastapi, p-cpe:/a:fedoraproject:fedora:python-starlette

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 2/14/2023

Vulnerability Publication Date: 2/14/2023

Reference Information