Cubic catastrophic backtracking (ReDoS) in marked
Published Jan 14, 2022
7.5
HIGHCVSS 3.1
EPSS 2.85%
Description
Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against some strings and lead to a regular expression denial of service (ReDoS). Anyone who runs untrusted markdown through a vulnerable version of marked and does not use a worker with a time limit may be affected. This issue is patched in version 4.0.10. As a workaround, avoid running untrusted markdown through marked or run marked on a worker thread and set a reasonable time limit to prevent draining resources.
Affected products
-
- Version < 4.0.10StatusaffectedConstraints-
- Version
Configuration 1
- < 4.0.10
Configuration 2
- 36
No data.
Red Hat Ceph Storage 6.1
rhceph/rhceph-6-dashboard-rhel9:6-75
Fixed · RHSA-2023:3642
OpenShift Service Mesh 2.0
servicemesh-grafana
Affected
OpenShift Service Mesh 2.1
servicemesh-grafana
Will not fix
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/console-rhel8
Will not fix
Red Hat Ceph Storage 5
ceph
Not affected
Red Hat Ceph Storage 5
rhceph/rhceph-5-dashboard-rhel8
Affected
Red Hat Data Grid 8
marked
Not affected
Red Hat Enterprise Linux 8
389-ds:1.4/389-ds-base
Will not fix
Red Hat Enterprise Linux 8
cockpit
Not affected
Red Hat Enterprise Linux 8
cockpit-appstream
Not affected
Red Hat Enterprise Linux 8
container-tools:2.0/cockpit-podman
Not affected
Red Hat Enterprise Linux 8
container-tools:rhel8/cockpit-podman
Not affected
Red Hat Enterprise Linux 8
grafana
Not affected
Red Hat Enterprise Linux 9
ceph
Will not fix
Red Hat Enterprise Linux 9
grafana
Not affected
Red Hat Fuse 7
marked
Not affected
Red Hat Integration Camel K 1
marked
Not affected
Red Hat Integration Data Virtualisation Operator
marked
Out of support scope
Red Hat Integration Service Registry
marked
Out of support scope
Red Hat JBoss Data Grid 7
marked
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
marked
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
marked
Not affected
Red Hat OpenShift GitOps
openshift-gitops-1/argocd-rhel8
Affected
Red Hat Single Sign-On 7
marked
Not affected
Red Hat build of Apicurio Registry 2
marked
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 6.1 | rhceph/rhceph-6-dashboard-rhel9:6-75 | Fixed | RHSA-2023:3642 |
| OpenShift Service Mesh 2.0 | servicemesh-grafana | Affected | n/a |
| OpenShift Service Mesh 2.1 | servicemesh-grafana | Will not fix | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/console-rhel8 | Will not fix | n/a |
| Red Hat Ceph Storage 5 | ceph | Not affected | n/a |
| Red Hat Ceph Storage 5 | rhceph/rhceph-5-dashboard-rhel8 | Affected | n/a |
| Red Hat Data Grid 8 | marked | Not affected | n/a |
| Red Hat Enterprise Linux 8 | 389-ds:1.4/389-ds-base | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | cockpit | Not affected | n/a |
| Red Hat Enterprise Linux 8 | cockpit-appstream | Not affected | n/a |
| Red Hat Enterprise Linux 8 | container-tools:2.0/cockpit-podman | Not affected | n/a |
| Red Hat Enterprise Linux 8 | container-tools:rhel8/cockpit-podman | Not affected | n/a |
| Red Hat Enterprise Linux 8 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 9 | ceph | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | grafana | Not affected | n/a |
| Red Hat Fuse 7 | marked | Not affected | n/a |
| Red Hat Integration Camel K 1 | marked | Not affected | n/a |
| Red Hat Integration Data Virtualisation Operator | marked | Out of support scope | n/a |
| Red Hat Integration Service Registry | marked | Out of support scope | n/a |
| Red Hat JBoss Data Grid 7 | marked | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | marked | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | marked | Not affected | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/argocd-rhel8 | Affected | n/a |
| Red Hat Single Sign-On 7 | marked | Not affected | n/a |
| Red Hat build of Apicurio Registry 2 | marked | Not affected | n/a |
marked
npm
Introduced 0 Fixed 4.0.10
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | marked | 0 | 4.0.10 |
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-21680 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2082705 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-0691 Advisory
- https://github.com/advisories/GHSA-rrrm-qjm4-v8hf Advisory
- https://github.com/markedjs/marked/commit/c4a3ccd344b6929afa8a1d50ac54a721e57012c0 PatchThird Party Advisory
- https://github.com/markedjs/marked/releases/tag/v4.0.10 Release NotesThird Party Advisory
- https://github.com/markedjs/marked/security/advisories/GHSA-rrrm-qjm4-v8hf ExploitThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AIXDMC3CSHYW3YWVSQOXAWLUYQHAO5UX/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AIXDMC3CSHYW3YWVSQOXAWLUYQHAO5UX/
- https://nvd.nist.gov/vuln/detail/CVE-2022-21680
- https://www.cve.org/CVERecord?id=CVE-2022-21680
Change history (0)
No recorded changes yet.