Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-22051

Опубликовано: 04 янв. 2024
Источник: redhat
CVSS3: 7.5

Описание

CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.

An integer overflow in cmark-gfm's table row parsing may lead to heap memory corruption when parsing tables who's marker rows contain more than UINT16_MAX columns.

Отчет

The way the commonmarker gem is used in API Management Platform, doesn't allow for any significant crossing of security boundaries.

Меры по смягчению последствий

Disabling any use of the table extension of cmark-gfm will prevent this vulnerability from being triggered.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 2commonmarkerAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2256887commonmarker: integer overflow in cmark-gfm's table row parsing may lead to heap memory corruption

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 2 лет назад

CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.

CVSS3: 9.8
nvd
около 2 лет назад

CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.

CVSS3: 9.8
debian
около 2 лет назад

CommonMarker versions prior to 0.23.4 are at risk of an integer overfl ...

CVSS3: 8.8
github
почти 4 года назад

Integer overflow in cmark-gfm table parsing extension leads to heap memory corruption

CVSS3: 9.8
fstec
около 2 лет назад

Уязвимость библиотеки CommonMarker, связанная с целочисленным переполнением, позволяющая нарушителю выполнить произвольный код

7.5 High

CVSS3