PT-2024-18406 · Unknown · Showdownjs

Shay Yaish

·

Published

2024-02-26

·

Updated

2024-08-01

·

CVE-2024-1899

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Showdownjs versions <= 2.1.0
Description An issue in the anchors subparser could allow a remote attacker to cause denial of service conditions.
Recommendations For versions <= 2.1.0, update to a version greater than 2.1.0 to resolve the issue. As a temporary workaround, consider restricting access to the anchors subparser until a patch is available.

Exploit

Fix

Uncontrolled Recursion

Weakness Enumeration

Related Identifiers

CVE-2024-1899
GHSA-RMMH-P597-PPVV

Affected Products

Showdownjs