PT-2020-17233 · Python+4 · Py+4

Published

2020-09-03

·

Updated

2025-11-03

·

CVE-2020-29651

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions py versions through 1.9.0
Description A denial of service via regular expression in the py.path.svnwc component could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality.
Recommendations For versions through 1.9.0, update to a version later than 1.9.0 to resolve the issue. As a temporary workaround, consider restricting the input to the blame functionality to minimize the risk of exploitation.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-03934
CVE-2020-29651
DLA-3966-1
GHSA-HJ5V-574P-MJ7C
MGASA-2021-0071
OESA-2022-1562
OPENSUSE-SU-2021:0851-1
OPENSUSE-SU-2021:1859-1
OPENSUSE-SU-2021_0851-1
OPENSUSE-SU-2021_1859-1
OPENSUSE-SU-2022_2831-1
OPENSUSE-SU-2024:11108-1
OPENSUSE-SU-2024:11252-1
OPENSUSE-SU-2024:14153-1
PYSEC-2020-92
SUSE-FU-2022:0444-1
SUSE-FU-2022:0445-1
SUSE-SU-2021:1859-1
SUSE-SU-2021:1962-1
SUSE-SU-2021:1963-1
SUSE-SU-2021:2236-1
SUSE-SU-2021:2554-1
SUSE-SU-2021_1859-1
SUSE-SU-2021_2236-1
SUSE-SU-2022:2831-1
SUSE-SU-2022_2831-1
USN-5138-1

Affected Products

Astra Linux
Linuxmint
Suse
Ubuntu
Py