CVE-2022-40896
Publication date 19 July 2023
Last updated 26 November 2024
Ubuntu priority
Cvss 3 Severity Score
A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
Status
Package | Ubuntu Release | Status |
---|---|---|
pygments | 24.10 oracular |
Not affected
|
24.04 LTS noble |
Not affected
|
|
22.04 LTS jammy |
Fixed 2.11.2+dfsg-2ubuntu0.1
|
|
20.04 LTS focal | Ignored code not present | |
18.04 LTS bionic | Ignored code not present | |
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
Notes
hlibk
This CVE is comprised of Smithy, SQL/SQL+Jinja, and Java properties files ReDoS vulnerabilities. Smithy appears to only be included in jammy and above, while SQL/SQL+Jinja appears to not be included in jammy and below, and fixed by upstream in later versions. Java properties issue appears to be vulnerable for bionic, focal, and jammy, but the fix requires a new feature release and older versions are not maintained by upstream.
Severity score breakdown
Parameter | Value |
---|---|
Base score | 5.5 · Medium |
Attack vector | Local |
Attack complexity | Low |
Privileges required | None |
User interaction | Required |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-7128-1
- Pygments vulnerability
- 26 November 2024