PT-2022-15024 · Unknown · Markdown-It
Makenowjust
+1
·
Published
2022-01-10
·
Updated
2023-07-24
·
CVE-2022-21670
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
markdown-it versions prior to 12.3.2
Description
The issue concerns a Markdown parser that can be significantly slowed down by special patterns with lengths greater than 50 thousand characters. There are no known real-world incidents or estimated numbers of affected devices provided.
Recommendations
For versions prior to 12.3.2, upgrade to version 12.3.2 or later to receive a patch. As there are no known workarounds aside from upgrading, it is essential to apply this update to mitigate the issue.
Exploit
Fix
Resource Exhaustion
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Markdown-It