Lucene search

K
ubuntucveUbuntu.comUB:CVE-2020-28493
HistoryFeb 01, 2021 - 12:00 a.m.

CVE-2020-28493

2021-02-0100:00:00
ubuntu.com
ubuntu.com
20
cve-2020-28493
jinja2
redos
vulnerability
markdown
user content
request timeouts

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS

0.002

Percentile

57.3%

This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS
vulnerability is mainly due to the _punctuation_re regex operator and its
use of multiple wildcards. The last wildcard is the most exploitable as it
searches for trailing punctuation. This issue can be mitigated by Markdown
to format user content instead of the urlize filter, or by implementing
request timeouts and limiting process memory.

Notes

Author Note
sbeattie regular expression DoS
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchjinja2< 2.10-1ubuntu0.18.04.1+esm1UNKNOWN
ubuntu20.04noarchjinja2< 2.10.1-2ubuntu0.2UNKNOWN
ubuntu14.04noarchjinja2< 2.7.2-2ubuntu0.1~esm2UNKNOWN
ubuntu16.04noarchjinja2< 2.8-1ubuntu0.1+esm1UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS

0.002

Percentile

57.3%