PT-2023-11360 · Unknown · Simple-Markdown

Published

2023-02-12

·

Updated

2024-05-17

·

CVE-2019-25102

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions simple-markdown version 0.6.0
Description A problematic vulnerability was found in the simple-markdown software, affecting an unknown function of the file simple-markdown.js. The issue arises from inefficient regular expression complexity when the input <<<<<<<<:/:/:/:/:/:/:/:/:/:/ is manipulated. This can be exploited remotely. The exploit has been publicly disclosed and may be used.
Recommendations To address this issue, upgrade to version 0.6.1. As a temporary workaround, consider restricting the input to prevent inefficient regular expression complexity until the upgrade is applied.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2019-25102
GHSA-J533-2G8V-PMPG

Affected Products

Simple-Markdown