CVE-2022-3301: rdiffweb vulnerable to Improper Cleanup on Thrown Exception
2.4
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.20986%
CWE
Published
9/27/2022
Updated
10/25/2024
KEV Status
No
Technology
Python
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| rdiffweb | pip | < 2.4.8 | 2.4.8 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The GitHub patch modifies the error_page function to replace the message with a generic one for 404 errors, explicitly stating the default implementation leaked path info. The added test case in test_page_error.py demonstrates the vulnerability by checking for path sanitization. The CWE-460 description matches this pattern of improper exception cleanup exposing sensitive information through unhandled error messages.