CVE-2020-28493

medium
Published 2021-03-19 ยท Modified 2021-11-09
CVSS v3
โ€”
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.5

Description

RHSA-2021:4162: python38:3.8 and python38-devel:3.8 security update (Moderate)

Predictions

Exploit likelihood
30%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata โ€” Red Hat Inc. ยท View original โ†— ยท Open-Errata-API

Description python-jinja2: ReDoS vulnerability in the urlize filter Red Hat statement This flaw is out of support scope for the following products: * Red Hat Enterprise Linux 6 * Red Hat Enterprise Linux 7 * Red Hat Ceph Storage 2 To learn more about Red Hat Enterprise Linux support scopes, please see https://access.redhat.com/support/policy/updates/errata/ In Red Hat OpenStack Platform, becauseโ€ฆ

Description

python-jinja2: ReDoS vulnerability in the urlize filter

Red Hat statement

This flaw is out of support scope for the following products: * Red Hat Enterprise Linux 6 * Red Hat Enterprise Linux 7 * Red Hat Ceph Storage 2 To learn more about Red Hat Enterprise Linux support scopes, please see https://access.redhat.com/support/policy/updates/errata/ In Red Hat OpenStack Platform, because python-jinja2 is not directly customer exposed, the Impact has been moved to Low and no updated will be provided at this time for the RHOSP python-jinja2 package. Red Hat Quay does not make use of the vulnerable function, so the impact is Low.

CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 8python27:2.7-8050020210811095446.3e7ace8bRHSA-2021:41512021-11-09T00:00:00Z
Red Hat Enterprise Linux 8python-jinja2-0:2.10.1-3.el8RHSA-2021:41612021-11-09T00:00:00Z
Red Hat Enterprise Linux 8python38:3.8-8050020210811101222.e3d35ccaRHSA-2021:41622021-11-09T00:00:00Z
Red Hat Enterprise Linux 8python38-devel:3.8-8050020210811101222.e3d35ccaRHSA-2021:41622021-11-09T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7python27-babel-0:0.9.6-10.el7RHSA-2021:32522021-08-24T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7python27-python-0:2.7.18-3.el7RHSA-2021:32522021-08-24T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7python27-python-jinja2-0:2.6-16.el7RHSA-2021:32522021-08-24T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7python27-python-pygments-0:1.5-5.el7RHSA-2021:32522021-08-24T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-python38-babel-0:2.7.0-12.el7RHSA-2021:32542021-08-24T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-python38-python-0:3.8.11-2.el7RHSA-2021:32542021-08-24T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-python38-python-cryptography-0:2.8-5.el7RHSA-2021:32542021-08-24T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-python38-python-jinja2-0:2.10.3-6.el7RHSA-2021:32542021-08-24T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-python38-python-lxml-0:4.4.1-7.el7RHSA-2021:32542021-08-24T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-python38-python-pip-0:19.3.1-2.el7RHSA-2021:32542021-08-24T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-python38-python-urllib3-0:1.25.7-7.el7RHSA-2021:32542021-08-24T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSpython27-babel-0:0.9.6-10.el7RHSA-2021:32522021-08-24T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSpython27-python-0:2.7.18-3.el7RHSA-2021:32522021-08-24T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSpython27-python-jinja2-0:2.6-16.el7RHSA-2021:32522021-08-24T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSpython27-python-pygments-0:1.5-5.el7RHSA-2021:32522021-08-24T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSrh-python38-babel-0:2.7.0-12.el7RHSA-2021:32542021-08-24T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSrh-python38-python-0:3.8.11-2.el7RHSA-2021:32542021-08-24T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSrh-python38-python-cryptography-0:2.8-5.el7RHSA-2021:32542021-08-24T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSrh-python38-python-jinja2-0:2.10.3-6.el7RHSA-2021:32542021-08-24T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSrh-python38-python-lxml-0:4.4.1-7.el7RHSA-2021:32542021-08-24T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSrh-python38-python-pip-0:19.3.1-2.el7RHSA-2021:32542021-08-24T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSrh-python38-python-urllib3-0:1.25.7-7.el7RHSA-2021:32542021-08-24T00:00:00Z

Package state

ProductPackageState
Red Hat Ansible Automation Platform 1.2jinja2Not affected
Red Hat Ansible Automation Platform 1.2python-jinja2Not affected
Red Hat Ansible Tower 3jinja2Not affected
Red Hat Ceph Storage 2python-jinja2Out of support scope
Red Hat Ceph Storage 3python-jinja2Will not fix
Red Hat Enterprise Linux 6python-jinja2Out of support scope
Red Hat Enterprise Linux 7python-jinja2Out of support scope
Red Hat Enterprise Linux 9python-jinja2Not affected
Red Hat OpenStack Platform 13 (Queens)python-jinja2Will not fix
Red Hat Quay 3quay/quay-rhel8Affected
Red Hat Satellite 6python-jinja2Affected

Apply commands

bash fix
Apply RHSA-2021:4151 for Red Hat Enterprise Linux 8
yum update -y python27:2
# or:
dnf upgrade -y python27:2

Affected

VendorProductVersion
redhatRed Hat Ansible Automation Platform 1.2Not affected
redhatRed Hat Ansible Automation Platform 1.2Not affected
redhatRed Hat Ansible Tower 3Not affected
redhatRed Hat Enterprise Linux 9Not affected
redhatRed Hat Quay 3Affected
redhatRed Hat Satellite 6Affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
8 Fixed python3-jinja2-2.10.1-3.el8.noarch.rpm
arch Arch Fixed 1 release
VersionStatusFixed in
โ€” Fixed 2.11.3-1
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2.11.3-1
sid Fixed 2.11.3-1
forky Fixed 2.11.3-1
bullseye Fixed 2.11.3-1
bookworm Fixed 2.11.3-1
redhat Red Hat Fixed 1 release
VersionStatusFixed in
8 Fixed โ€”
rockylinux Rocky Linux Fixed 1 release
VersionStatusFixed in
8 Fixed โ€”

Package impact

EcosystemPackageVulnerableFixed
python PyPIjinja2<2.11.32.11.3

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.