Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4r62-v4vq-hr96

Опубликовано: 08 фев. 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Regular Expression Denial of Service (REDoS) in Marked

Impact

What kind of vulnerability is it? Who is impacted?

Regular expression Denial of Service

A Denial of Service attack can affect anyone who runs user generated code through marked.

Patches

Has the problem been patched? What versions should users upgrade to?

patched in v2.0.0

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?

None.

References

Are there any links users can visit to find out more?

https://github.com/markedjs/marked/issues/1927 https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

marked

npm
Затронутые версииВерсия исправления

>= 1.1.1, < 2.0.0

2.0.0

EPSS

Процентиль: 69%
0.00603
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
redhat
около 5 лет назад

Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before version 2.0.0, there is a Regular expression Denial of Service vulnerability. This vulnerability can affect anyone who runs user generated code through marked. This vulnerability is fixed in version 2.0.0.

CVSS3: 5.3
nvd
почти 5 лет назад

Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before version 2.0.0, there is a Regular expression Denial of Service vulnerability. This vulnerability can affect anyone who runs user generated code through marked. This vulnerability is fixed in version 2.0.0.

CVSS3: 5.3
debian
почти 5 лет назад

Marked is an open-source markdown parser and compiler (npm package "ma ...

EPSS

Процентиль: 69%
0.00603
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-400