simple-markdown simple-markdown.js redos
Published Feb 12, 2023
7.5
HIGHCVSS 3.1
EPSS 1.10%
Description
A vulnerability, which was classified as problematic, was found in simple-markdown 0.6.0. Affected is an unknown function of the file simple-markdown.js. The manipulation with the input <<<<<<<<<<:/:/:/:/:/:/:/:/:/:/ leads to inefficient regular expression complexity. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.6.1 is able to address this issue. The patch is identified as 015a719bf5cdc561feea05500ecb3274ef609cd2. It is recommended to upgrade the affected component. VDB-220638 is the identifier assigned to this vulnerability.
Affected products
- Vendor n/a Product Simple-Markdown Defaultn/a
- Version 0.6.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Simple-Markdown | n/a |
|
- 0.6.0
No data.
No Red Hat product state for this CVE.
simple-markdown
npm
Introduced 0 Fixed 0.6.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | simple-markdown | 0 | 0.6.1 |
Remediation
No remediation recorded yet.
References (7)
- https://github.com/advisories/GHSA-j533-2g8v-pmpg Advisory
- https://github.com/ariabuckles/simple-markdown/commit/015a719bf5cdc561feea05500ecb3274ef609cd2 patch
- https://github.com/ariabuckles/simple-markdown/pull/73 exploitissue-trackingIssue TrackingPatch
- https://github.com/ariabuckles/simple-markdown/releases/tag/0.6.1 patchRelease Notes
- https://nvd.nist.gov/vuln/detail/CVE-2019-25102
- https://vuldb.com/?ctiid.220638 signaturepermissions-requiredPermissions RequiredThird Party Advisory
- https://vuldb.com/?id.220638 vdb-entrytechnical-descriptionPermissions RequiredThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-j533-2g8v-pmpg | Advisory | |
| https://github.com/ariabuckles/simple-markdown/commit/015a719bf5cdc561feea05500ecb3274ef609cd2 | patch | |
| https://github.com/ariabuckles/simple-markdown/pull/73 | exploitissue-trackingIssue TrackingPatch | |
| https://github.com/ariabuckles/simple-markdown/releases/tag/0.6.1 | patchRelease Notes | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-25102 | ||
| https://vuldb.com/?ctiid.220638 | signaturepermissions-requiredPermissions RequiredThird Party Advisory | |
| https://vuldb.com/?id.220638 | vdb-entrytechnical-descriptionPermissions RequiredThird Party Advisory |
Change history (0)
No recorded changes yet.