Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-21680

Опубликовано: 14 янв. 2022
Источник: redhat
CVSS3: 7.5

Описание

Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression block.def may cause catastrophic backtracking against some strings and lead to a regular expression denial of service (ReDoS). Anyone who runs untrusted markdown through a vulnerable version of marked and does not use a worker with a time limit may be affected. This issue is patched in version 4.0.10. As a workaround, avoid running untrusted markdown through marked or run marked on a worker thread and set a reasonable time limit to prevent draining resources.

A vulnerability was found in the markedjs package. Affected versions of this package are vulnerable to Regular expression Denial of Service (ReDoS) attacks, affecting system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 2.0servicemesh-grafanaAffected
OpenShift Service Mesh 2.1servicemesh-grafanaWill not fix
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel8Will not fix
Red Hat build of Apicurio Registry 2markedNot affected
Red Hat Ceph Storage 5cephAffected
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Affected
Red Hat Data Grid 8markedNot affected
Red Hat Enterprise Linux 8389-ds:1.4/389-ds-baseWill not fix
Red Hat Enterprise Linux 8cockpitNot affected
Red Hat Enterprise Linux 8cockpit-appstreamNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-186
https://bugzilla.redhat.com/show_bug.cgi?id=2082705marked: regular expression block.def may lead Denial of Service

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 4 лет назад

Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against some strings and lead to a regular expression denial of service (ReDoS). Anyone who runs untrusted markdown through a vulnerable version of marked and does not use a worker with a time limit may be affected. This issue is patched in version 4.0.10. As a workaround, avoid running untrusted markdown through marked or run marked on a worker thread and set a reasonable time limit to prevent draining resources.

CVSS3: 7.5
nvd
около 4 лет назад

Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against some strings and lead to a regular expression denial of service (ReDoS). Anyone who runs untrusted markdown through a vulnerable version of marked and does not use a worker with a time limit may be affected. This issue is patched in version 4.0.10. As a workaround, avoid running untrusted markdown through marked or run marked on a worker thread and set a reasonable time limit to prevent draining resources.

CVSS3: 7.5
debian
около 4 лет назад

Marked is a markdown parser and compiler. Prior to version 4.0.10, the ...

CVSS3: 7.5
github
около 4 лет назад

Inefficient Regular Expression Complexity in marked

CVSS3: 7.5
fstec
около 4 лет назад

Уязвимость анализатора и компилятора уценки Marked, связанная с некорректной обработкой регулярного выражения, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3