Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-20270

Опубликовано: 10 дек. 2020
Источник: redhat
CVSS3: 7.5

Описание

An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.

Отчет

In OpenShift Container Platform 3.11, the vulnerable version of python-pygments is embedded in the google-cloud-sdk package, which is shipped in the openshift-ansible container (aos3-installation-container). As the access to the openshift-ansible container is restricted only to cluster administrators, this component is affected but with a Low impact. The google-cloud-sdk package was shipped in OpenShift Container Platform 4.1, which is End of Life.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6python-pygmentsNot affected
Red Hat Enterprise Linux 7python-pygmentsNot affected
Red Hat Enterprise Linux 7resource-agentsOut of support scope
Red Hat Enterprise Linux 9python-pygmentsNot affected
Red Hat OpenShift Container Platform 3.11google-cloud-sdkFix deferred
Red Hat OpenShift Container Platform 4google-cloud-sdkOut of support scope
Red Hat OpenStack Platform 10 (Newton)python-pygmentsOut of support scope
Red Hat Automation Hub 4.2 for RHEL 7automation-hubFixedRHSA-2021:078109.03.2021
Red Hat Automation Hub 4.2 for RHEL 7python3-djangoFixedRHSA-2021:078109.03.2021
Red Hat Automation Hub 4.2 for RHEL 7python-bleachFixedRHSA-2021:078109.03.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1922136python-pygments: Infinite loop in SML lexer may lead to DoS

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 4 лет назад

An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.

CVSS3: 7.5
nvd
около 4 лет назад

An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.

CVSS3: 7.5
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 7.5
debian
около 4 лет назад

An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lea ...

suse-cvrf
больше 3 лет назад

Security update for python-Pygments

7.5 High

CVSS3