Executive brief
Cleo, a Python library used for creating command-line interfaces, is vulnerable to a denial-of-service attack. By providing specially crafted input to the library's table-rendering feature, an attacker can cause the application to consume excessive CPU resources. This can lead to the application becoming unresponsive or crashing, potentially disrupting services that rely on this library to process user-supplied data.
Technical details
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the cleo library (versions 1.0.0a1 through 2.0.0) due to inefficient regular expression complexity (CWE-1333). The vulnerability is located within the Table.set_rows method, where an attacker can supply arbitrary input that triggers exponential backtracking in the regex engine. While the attack complexity is rated as high, a successful exploit allows a remote attacker to cause a sustained denial-of-service condition by exhausting CPU resources. The issue is resolved in version 2.0.0.
Affected products
- python-poetry cleo >= 1.0.0a1, < 2.0.0
Timeline
- 2022-11-09: disclosed: NVD publication date
- 2022-11-10: advisory: GitHub Advisory published
- 2022-11-10: patched: GitHub Advisory marked as reviewed and patched version identified