Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-26302

Опубликовано: 23 фев. 2023
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Denial of service could be caused to the command line interface of markdown-it-py, before v2.2.0, if an attacker was allowed to use invalid UTF-8 characters as input.

A denial of service vulnerability exists in markdown-it-py.An attacker could craft a payload with invalid UTF-8 characters as input to cause a crash thereby affecting the availability

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-lintNot affected
Red Hat Ansible Automation Platform 2ansible-navigatorNot affected
Red Hat Ansible Automation Platform 2python3x-ansible-compatNot affected
Red Hat Ansible Automation Platform 2python-ansible-compatNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2175697markdown-it-py: Denial of service in the command line interface due to invalid UTF-8 characters as input.

EPSS

Процентиль: 5%
0.00022
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
почти 3 года назад

Denial of service could be caused to the command line interface of markdown-it-py, before v2.2.0, if an attacker was allowed to use invalid UTF-8 characters as input.

CVSS3: 3.3
nvd
почти 3 года назад

Denial of service could be caused to the command line interface of markdown-it-py, before v2.2.0, if an attacker was allowed to use invalid UTF-8 characters as input.

CVSS3: 3.3
debian
почти 3 года назад

Denial of service could be caused to the command line interface of mar ...

CVSS3: 5.5
github
почти 3 года назад

markdown-it-py Denial of Service vulnerability in the command line interface

EPSS

Процентиль: 5%
0.00022
Низкий

5.5 Medium

CVSS3