CVE-2020-28493

CVE-2020-28493

This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDOS vulnerability of the regex is mainly due to the sub-pattern [a-zA-Z0-9._-]+.[a-zA-Z0-9._-]+ This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.

Source: CVE-2020-28493

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다