VDB
BDU%3A2025-09877
BDU%3A2025-09877
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость реализация логики подписи запросов OAuth для Python OAuthLib, связанная с недостаточной проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., ООО «Ред Софт», Red Hat Inc., Сообщество свободного программного обеспечения | openSUSE Tumbleweed, РЕД ОС (запись в едином реестре российских программ №3751), Red Hat OpenShift Container Platform, Red Hat Enterprise Linux, Red Hat Ansible Automation Platform, SUSE Liberty Linux, Suse Linux Enterprise Desktop, Suse Linux Enterprise Server, SUSE Linux Enterprise Server for SAP Applications, SUSE Linux Enterprise High Performance Computing, SUSE Linux Enterprise Micro, SUSE Linux Enterprise Module for Python 3, OAuthLib |
Timeline
- Aug 18, 2025 CVE Published
References
- https://www.suse.com/ko-kr/security/cve/CVE-2022-36087.html url
- https://github.com/oauthlib/oauthlib/commit/2e40b412c844ecc4673c3fa3f72181f228bdbacd url
- https://access.redhat.com/security/cve/CVE-2022-36087 url
- https://redos.red-soft.ru/support/secure/uyazvimosti/uyazvimost-python3-oauthlib-cve-2022-36087/?sphrase_id=1154397 advisory