Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-34749

Опубликовано: 26 июл. 2022
Источник: redhat
CVSS3: 7.5

Описание

In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.

A regular expression denial of service (ReDoS) flaw was found in the asteris emphasis regular expression implementation in Mistune. By sending specially-crafted regex input, a remote attacker could invoke a catastrophic backtrack, resulting in a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 6python-mistuneAffected
Red Hat Ceph Storage 7python-mistuneAffected
Red Hat OpenShift Container Platform 4python-mistuneAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2112230mistune: catastrophic backtracking

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.

CVSS3: 7.5
nvd
больше 3 лет назад

In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.

CVSS3: 7.5
msrc
больше 3 лет назад

In mistune through 2.0.2 support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.

CVSS3: 7.5
debian
больше 3 лет назад

In mistune through 2.0.2, support of inline markup is implemented by u ...

CVSS3: 8.6
github
больше 3 лет назад

Mistune vulnerable to catastrophic backtracking

7.5 High

CVSS3