Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pq64-v7f5-gqh8

Опубликовано: 29 мар. 2021
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Pygments vulnerable to Regular Expression Denial of Service (ReDoS)

In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service.

Пакеты

Наименование

Pygments

pip
Затронутые версииВерсия исправления

>= 1.1, < 2.7.4

2.7.4

EPSS

Процентиль: 87%
0.0372
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service.

CVSS3: 7.5
redhat
больше 4 лет назад

In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service.

CVSS3: 7.5
nvd
больше 4 лет назад

In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service.

CVSS3: 7.5
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 4 лет назад

In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming ...

EPSS

Процентиль: 87%
0.0372
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400