QID 982900

QID 982900: Python (pip) Security Update for jinja2 (GHSA-g3rq-g295-4j3m)

This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDOS vulnerability of the regex is mainly due to the sub-pattern [a-zA-Z0-9._-]+.[a-zA-Z0-9._-]+ This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-g3rq-g295-4j3m for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982900

    Software Advisories
    Advisory ID Software Component Link
    GHSA-g3rq-g295-4j3m jinja2 URL Logo github.com/advisories/GHSA-g3rq-g295-4j3m