PT-2022-15024 · Unknown · Markdown-It

Makenowjust

+1

·

Published

2022-01-10

·

Updated

2023-07-24

·

CVE-2022-21670

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions markdown-it versions prior to 12.3.2
Description The issue concerns a Markdown parser that can be significantly slowed down by special patterns with lengths greater than 50 thousand characters. There are no known real-world incidents or estimated numbers of affected devices provided.
Recommendations For versions prior to 12.3.2, upgrade to version 12.3.2 or later to receive a patch. As there are no known workarounds aside from upgrading, it is essential to apply this update to mitigate the issue.

Exploit

Fix

Resource Exhaustion

DoS

Weakness Enumeration

Related Identifiers

CVE-2022-21670
GHSA-6VFC-QV3F-VR6C

Affected Products

Markdown-It