{"id":"CVE-2022-3301","aliases":["GHSA-qq29-5vjh-vxwr","PYSEC-2022-295"],"url":"https://o3.security/vulnerability/CVE-2022-3301","summary":"Improper Cleanup on Thrown Exception in ikus060/rdiffweb","details":"rdiffweb prior to version 2.4.8 is vulnerable to Improper Cleanup on Thrown Exception. This could allow an attacker to display a message of their choice onto a web page. Version 2.4.8 contains a fix for this issue.","published":"2022-09-26T11:10:09Z","modified":"2026-09-19T03:45:59.462425446Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"},"epss":{"score":0.00599,"percentile":0.46519,"asOf":"2026-09-07"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"rdiffweb","fixedVersion":"2.4.8"}],"fix":{"url":"https://github.com/ikus060/rdiffweb/commit/5ac38b2a75becbab9f948bd5e37ecbcd9f0b362e","label":"ikus060/rdiffweb@5ac38b2"},"references":[{"type":"WEB","url":"https://huntr.dev/bounties/d3bf1e5d-055a-44b8-8d60-54ab966ed63a"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/3xxx/CVE-2022-3301.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-3301"},{"type":"FIX","url":"https://github.com/ikus060/rdiffweb/commit/5ac38b2a75becbab9f948bd5e37ecbcd9f0b362e"},{"type":"PACKAGE","url":"https://github.com/ikus060/rdiffweb"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/rdiffweb/PYSEC-2022-295.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-19T03:45:59.462425446Z"}}