PT-2021-17146 · Markdown2+1 · Markdown2+1
Ben Caller
·
Published
2021-03-03
·
Updated
2024-07-12
·
CVE-2021-26813
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
markdown2 versions 1.0.1.18 through 2.3.x
Description:
The issue allows an attacker to cause a denial of service by providing a malicious string, making markdown2 processing difficult or delayed for an extended period. This occurs due to a regular expression denial of service vulnerability.
Recommendations:
For markdown2 versions 1.0.1.18 through 2.3.x, update to version 2.4.0 to resolve the issue.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Markdown2