PT-2020-17233 · Python+4 · Py+4
Published
2020-09-03
·
Updated
2025-11-03
·
CVE-2020-29651
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
py versions through 1.9.0
Description
A denial of service via regular expression in the py.path.svnwc component could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality.
Recommendations
For versions through 1.9.0, update to a version later than 1.9.0 to resolve the issue.
As a temporary workaround, consider restricting the input to the blame functionality to minimize the risk of exploitation.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Suse
Ubuntu
Py