Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v638-q856-grg8

Опубликовано: 29 авг. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

MathJax Regular expression Denial of Service (ReDoS)

Mathjax up to v2.7.9 was discovered to contain two Regular expression Denial of Service (ReDoS) vulnerabilities in MathJax.js via the components pattern and markdownPattern. NOTE: the vendor disputes this because the regular expressions are not applied to user input; thus, there is no risk.

Пакеты

Наименование

mathjax

npm
Затронутые версииВерсия исправления

<= 2.7.9

Отсутствует

EPSS

Процентиль: 41%
0.00188
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

Mathjax up to v2.7.9 was discovered to contain two Regular expression Denial of Service (ReDoS) vulnerabilities in MathJax.js via the components pattern and markdownPattern. NOTE: the vendor disputes this because the regular expressions are not applied to user input; thus, there is no risk.

CVSS3: 7.5
nvd
больше 2 лет назад

Mathjax up to v2.7.9 was discovered to contain two Regular expression Denial of Service (ReDoS) vulnerabilities in MathJax.js via the components pattern and markdownPattern. NOTE: the vendor disputes this because the regular expressions are not applied to user input; thus, there is no risk.

CVSS3: 7.5
debian
больше 2 лет назад

Mathjax up to v2.7.9 was discovered to contain two Regular expression ...

EPSS

Процентиль: 41%
0.00188
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333