Lucene search

K
gitlabHttps://gitlab.com/gitlab-org/security-products/gemnasium-dbGITLAB-2B9F06DA84CB3AA272E072E600CA944E
HistoryFeb 01, 2021 - 12:00 a.m.

Regular Expression Denial of Service

2021-02-0100:00:00
https://gitlab.com/gitlab-org/security-products/gemnasium-db
gitlab.com
14

0.002 Low

EPSS

Percentile

57.4%

The ReDOS vulnerability of the regex is mainly due to the sub-pattern [a-zA-Z0-9._-]+.[a-zA-Z0-9._-]+ This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.

CPENameOperatorVersion
pypi/jinja2lt2.11.3