CVE-2020-29651: High severity pytest vulnerability
Published Dec 9, 2020
·Updated
A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality.
Affected Software
5 affected componentsFixes available
pip/py<1.10.0
1.10.0
pytest py<=1.9.0
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Oracle ZFS Storage Appliance Kit=8.8
Remediation
Event History
Dec 9, 2020
CVE Published
via MITRE·06:58 AM
Data Sourced
via MITRE·06:58 AM
Description
Data Sourced
via NVD·07:15 AM
RemedyDescriptionSeverityAffected Software
Apr 20, 2021
Advisory Published
via GitHub·04:39 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-29651?
CVE-2020-29651 has a medium severity rating due to its potential to cause denial of service.
2
How do I fix CVE-2020-29651?
To fix CVE-2020-29651, upgrade the py package to version 1.10.0 or later.
3
What components are affected by CVE-2020-29651?
CVE-2020-29651 affects the py.path.svnwc component of the py library in versions up to 1.9.0.
4
What type of attack does CVE-2020-29651 enable?
CVE-2020-29651 enables a compute-time denial of service attack through malicious input.
5
Which software versions are vulnerable to CVE-2020-29651?
Vulnerable software versions for CVE-2020-29651 include py versions before 1.10.0, pytest, and some specific versions of Fedora.