OESA-2023-1683
Dashboard / Vulnerabilities / OESA-2023-1683
Summary: python-mako security update
Details: Python-mako is a template library for Python. It provides a familiar, non-XML syntax which compiles into Python modules for maximum performance. Mako's syntax and API borrows from the best ideas of many others, including Django templates, Cheetah, Myghty, and Genshi. Security Fix(es): Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.(CVE-2022-40023)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1683, https://nvd.nist.gov/vuln/detail/CVE-2022-40023
Affected packages
Package
Name: python-mako
Purl: pkg:rpm/openEuler/python-mako&distro=openEuler-20.03-LTS-SP3
Affected ranges
Type: ECOSYSTEM
Events:
