CVE-2020-29651 is a denial-of-service vulnerability affecting the py.path.svnwc component of the 'py' Python library (also known as python-py) up to version 1.9.0, impacting products like Fedora and Oracle ZFS Storage Appliance Kit. Attackers can trigger a compute-time denial of service by providing malicious input to the blame functionality, exploiting a regular expression vulnerability. With a CVSS score of 7.5 (High), this network-exploitable vulnerability requires no privileges or user interaction, leading to a high availability impact. There is currently no evidence of active exploitation, no public exploit code available (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.9.0CPE matchmatch criteria | cpe:2.3:a:pytest:py:*:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
8.8CPE matchmatch criteria | cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
py vulnerable to Regular Expression Denial of Service
Apr 20, 2021A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality.
Dec 8, 2020python-py: ReDoS in the py.path.svnwc component via mailicious input to blame functionality
Sep 3, 2020