PT-2023-27062 · Mathjax · Mathjax

CVE-2023-39663

·

Publicado

2023-08-29

·

Atualizado

2024-08-02

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Mathjax versions up to v2.7.9
Description The issue concerns two Regular expression Denial of Service (ReDoS) vulnerabilities in MathJax.js via the components pattern and markdownPattern. However, the vendor disputes this, stating that the regular expressions are not applied to user input, thus posing no risk.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-39663
GHSA-V638-Q856-GRG8

Produtos afetados

Mathjax