PT-2022-11820 · Npm · Markdown-Link-Extractor

Denys Vozniuk

·

Published

2022-06-01

·

Updated

2023-07-18

·

CVE-2021-43308

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions markdown-link-extractor npm package (affected versions not specified)
Description The issue is related to an exponential ReDoS (Regular Expression Denial of Service) that can be triggered when an attacker supplies arbitrary input to the module's exported function. This allows for a potential denial-of-service attack.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43308
GHSA-MMH6-M7V9-5956

Affected Products

Markdown-Link-Extractor