Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-34749

Опубликовано: 26 июл. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.

A regular expression denial of service (ReDoS) flaw was found in the asteris emphasis regular expression implementation in Mistune. By sending specially-crafted regex input, a remote attacker could invoke a catastrophic backtrack, resulting in a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 6python-mistuneWill not fix
Red Hat OpenShift Container Platform 4python-mistuneAffected
Red Hat Ceph Storage 7.1cephFixedRHSA-2026:276917.02.2026
Red Hat Ceph Storage 8.1cephFixedRHSA-2026:271116.02.2026
Red Hat Ceph Storage 8rhceph/rhceph-8-rhel9FixedRHSA-2026:273716.02.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2112230mistune: catastrophic backtracking

EPSS

Процентиль: 72%
0.01483
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 4 лет назад

In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.

CVSS3: 7.5
nvd
около 4 лет назад

In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.

CVSS3: 7.5
msrc
около 4 лет назад

In mistune through 2.0.2 support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.

CVSS3: 7.5
debian
около 4 лет назад

In mistune through 2.0.2, support of inline markup is implemented by u ...

CVSS3: 8.6
github
около 4 лет назад

Mistune vulnerable to catastrophic backtracking

EPSS

Процентиль: 72%
0.01483
Низкий

7.5 High

CVSS3