A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
References
Configurations
History
21 Nov 2024, 07:22
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
References | () https://github.com/pygments/pygments/blob/master/pygments/lexers/smithy.py#L61 - Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZGMXALE3HSP4OXC7UUWIKX3OXKZDTY3/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VUZO4BQCIY2S2KZYHERQMKURB7AHXDBO/ - | |
References | () https://pypi.org/project/Pygments/ - Product | |
References | () https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages-part-2/ - Exploit, Patch, Third Party Advisory |
28 Mar 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
05 Feb 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
26 Jul 2023, 21:04
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-434 | |
References | (MISC) https://github.com/pygments/pygments/blob/master/pygments/lexers/smithy.py#L61 - Third Party Advisory | |
References | (MISC) https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages-part-2/ - Exploit, Patch, Third Party Advisory | |
References | (MISC) https://pypi.org/project/Pygments/ - Product | |
First Time |
Pygments
Pygments pygments |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
CPE | cpe:2.3:a:pygments:pygments:*:*:*:*:*:*:*:* |
19 Jul 2023, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-07-19 15:15
Updated : 2024-11-21 07:22
NVD link : CVE-2022-40896
Mitre link : CVE-2022-40896
CVE.ORG link : CVE-2022-40896
JSON object : View
Products Affected
pygments
- pygments
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type