Описание
Mistune vulnerable to catastrophic backtracking
In Mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2022-34749
- https://github.com/lepture/mistune/issues/314#issuecomment-1223972386
- https://github.com/lepture/mistune/commit/a6d43215132fe4f3d93f8d7e90ba83b16a0838b2
- https://github.com/lepture/mistune/commit/ca1e7b506850f4e488823fc7338b49a8f9852718
- https://github.com/lepture/mistune/releases
- https://github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2022-237.yaml
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TQHXITQ2DSBYOILKHXBSBB7PFBPZHF63
Пакеты
mistune
>= 2.0.0a1, < 2.0.3
2.0.3
Связанные уязвимости
In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.
In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.
In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.
In mistune through 2.0.2 support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.
In mistune through 2.0.2, support of inline markup is implemented by u ...