Логотип exploitDog
bind:"GHSA-g3rq-g295-4j3m" OR bind:"CVE-2020-28493"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-g3rq-g295-4j3m" OR bind:"CVE-2020-28493"

Количество 16

Количество 16

github логотип

GHSA-g3rq-g295-4j3m

больше 4 лет назад

Regular Expression Denial of Service (ReDoS) in Jinja2

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-28493

больше 4 лет назад

This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2020-28493

больше 4 лет назад

This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2020-28493

больше 4 лет назад

This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2020-28493

около 3 лет назад

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-28493

больше 4 лет назад

This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDo ...

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:14644-1

больше 4 лет назад

Security update for python-Jinja2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0654-1

больше 4 лет назад

Security update for python-Jinja2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0607-1

больше 4 лет назад

Security update for python-Jinja2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0601-1

больше 4 лет назад

Security update for python-Jinja2

EPSS: Низкий
rocky логотип

RLSA-2021:4161

больше 3 лет назад

Moderate: python-jinja2 security update

EPSS: Низкий
fstec логотип

BDU:2022-05230

больше 3 лет назад

Уязвимость инструмента для html-шаблонизации jinja2 интерпретатора языка программирования Python, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
EPSS: Низкий
rocky логотип

RLSA-2021:4151

больше 3 лет назад

Moderate: python27:2.7 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2021-4151

больше 3 лет назад

ELSA-2021-4151: python27:2.7 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2021-4162

больше 3 лет назад

ELSA-2021-4162: python38:3.8 and python38-devel:3.8 security update (MODERATE)

EPSS: Низкий
rocky логотип

RLSA-2021:4162

больше 3 лет назад

Moderate: python38:3.8 and python38-devel:3.8 security update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-g3rq-g295-4j3m

Regular Expression Denial of Service (ReDoS) in Jinja2

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2020-28493

This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2020-28493

This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2020-28493

This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 5.3
0%
Низкий
около 3 лет назад
debian логотип
CVE-2020-28493

This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDo ...

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:14644-1

Security update for python-Jinja2

0%
Низкий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:0654-1

Security update for python-Jinja2

0%
Низкий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:0607-1

Security update for python-Jinja2

0%
Низкий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:0601-1

Security update for python-Jinja2

0%
Низкий
больше 4 лет назад
rocky логотип
RLSA-2021:4161

Moderate: python-jinja2 security update

0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2022-05230

Уязвимость инструмента для html-шаблонизации jinja2 интерпретатора языка программирования Python, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
rocky логотип
RLSA-2021:4151

Moderate: python27:2.7 security update

больше 3 лет назад
oracle-oval логотип
ELSA-2021-4151

ELSA-2021-4151: python27:2.7 security update (MODERATE)

больше 3 лет назад
oracle-oval логотип
ELSA-2021-4162

ELSA-2021-4162: python38:3.8 and python38-devel:3.8 security update (MODERATE)

больше 3 лет назад
rocky логотип
RLSA-2021:4162

Moderate: python38:3.8 and python38-devel:3.8 security update

больше 3 лет назад

Уязвимостей на страницу