Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6vfc-qv3f-vr6c

Опубликовано: 12 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Uncontrolled Resource Consumption in markdown-it

Impact

Special patterns with length > 50K chars can slow down parser significantly.

const md = require('markdown-it')(); md.render(`x ${' '.repeat(150000)} x \nx`);

Patches

Upgrade to v12.3.2+

Workarounds

No.

References

Fix + test sample: https://github.com/markdown-it/markdown-it/commit/ffc49ab46b5b751cd2be0aabb146f2ef84986101

Пакеты

Наименование

markdown-it

npm
Затронутые версииВерсия исправления

< 12.3.2

12.3.2

EPSS

Процентиль: 80%
0.01394
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-1333
CWE-400

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 4 лет назад

markdown-it is a Markdown parser. Prior to version 1.3.2, special patterns with length greater than 50 thousand characterss could slow down the parser significantly. Users should upgrade to version 12.3.2 to receive a patch. There are no known workarounds aside from upgrading.

CVSS3: 5.3
nvd
около 4 лет назад

markdown-it is a Markdown parser. Prior to version 1.3.2, special patterns with length greater than 50 thousand characterss could slow down the parser significantly. Users should upgrade to version 12.3.2 to receive a patch. There are no known workarounds aside from upgrading.

CVSS3: 5.3
debian
около 4 лет назад

markdown-it is a Markdown parser. Prior to version 1.3.2, special patt ...

EPSS

Процентиль: 80%
0.01394
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-1333
CWE-400