PT-2023-27062 · Mathjax · Mathjax

Published

2023-08-29

·

Updated

2024-08-02

·

CVE-2023-39663

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Mathjax versions up to v2.7.9
Description The issue concerns two Regular expression Denial of Service (ReDoS) vulnerabilities in MathJax.js via the components pattern and markdownPattern. However, the vendor disputes this, stating that the regular expressions are not applied to user input, thus posing no risk.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Weakness Enumeration

Related Identifiers

CVE-2023-39663
GHSA-V638-Q856-GRG8

Affected Products

Mathjax