CVE-2020-23478

Source
https://cve.org/CVERecord?id=CVE-2020-23478
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-23478.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-23478
Aliases
Published
2021-09-22T20:15:08.077Z
Modified
2026-05-18T13:29:06.662173Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Leo Editor v6.2.1 was discovered to contain a regular expression denial of service (ReDoS) vulnerability in the component plugins/importers/dart.py.

References

Affected packages

Git / github.com/leo-editor/leo-editor

Affected ranges

Type
GIT
Repo
https://github.com/leo-editor/leo-editor
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "source": "CPE_FIELD",
    "cpe": "cpe:2.3:a:leoeditor:leo:6.2.1:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "6.2.1"
        }
    ]
}

Affected versions

Other
4-11-a2
Bug-135
Bug-149-stage-0-complete
Fixed-bug-149
Leo-4-4-8-b1
Leo-4-5-b1
Leo-4-5-b2
Leo-4-5-b3
before-open-with-work
before-until-4-7-final
before_unicode_mass_update
breaks-auto-completer
broke-abbrev
last-good-commit
last_working_recursive_import
leo-4-10-b1
leo-4-10-final
leo-4-11-a1
leo-4-11-b1
leo-4-11-final
leo-4-4-8-b2
leo-4-4-8-b3
leo-4-4-8-final
leo-4-4-8-rc1
leo-4-4-8-rc1-a
leo-4-5-1-august-14-2008
leo-4-5-1-final
leo-4-5-final
leo-4-5-rc1
leo-4-5-rc2
leo-4-6-b1
leo-4-6-b2
leo-4-7-1-final
leo-4-7-b2
leo-4-7-b2-as-released
leo-4-7-b3
leo-4-7-final
leo-4-7-rc1
leo-4-7-rc1-a
leo-4-7-rc1-b
leo-4-8-a1
leo-4-8-b1
leo-4-8-final
leo-4-8-rc1
leo-4-9-b1
leo-4-9-b2
leo-4-9-b4
leo-4-9-final
leo-4-9-rc1
leo-4-9-rc1-a
old-rst-code-last-rev
5.*
5.3
5.4
5.4-b1
5.4.1
5.5
5.5b1
5.7b1
5.7b2
Leo-5.*
Leo-5.0-a1
Leo-5.0-a2
Leo-5.0-b1
Leo-5.0-b2
Leo-5.0-final
Leo-5.1-b1
Leo-5.1-b2
Leo-5.1-final
leo-5.*
leo-5.0-a1
v5.*
v5.2
v6.*
v6.0b1
v6.2
v6.2-b1
v6.2.1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-23478.json"