REDHAT-BUG-2251643: Medium severity Pygments Pygments vulnerability
Published Nov 27, 2023
·Updated
A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
Affected Software
1 affected component
Pygments Pygments<=2.15.0
Event History
Nov 27, 2023
Data Sourced
via Red Hat·03:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2251643?
The severity of REDHAT-BUG-2251643 is categorized as a ReDoS (Regular Expression Denial of Service) vulnerability.
2
What versions of Pygments are affected by REDHAT-BUG-2251643?
Pygments versions up to and including 2.15.0 are affected by REDHAT-BUG-2251643.
3
How do I fix REDHAT-BUG-2251643?
To fix REDHAT-BUG-2251643, update Pygments to a version above 2.15.0.
4
What component of Pygments does REDHAT-BUG-2251643 impact?
REDHAT-BUG-2251643 impacts the SmithyLexer component in pygments/lexers/smithy.py.
5
Is a workaround available for REDHAT-BUG-2251643?
There is currently no documented workaround for REDHAT-BUG-2251643; the best option is to update the library.