PT-2022-15024 · Unknown · Markdown-It

·

CVE-2022-21670

·

Published

2022-01-10

·

Updated

2023-07-24

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions markdown-it versions prior to 12.3.2
Description The issue concerns a Markdown parser that can be significantly slowed down by special patterns with lengths greater than 50 thousand characters. There are no known real-world incidents or estimated numbers of affected devices provided.
Recommendations For versions prior to 12.3.2, upgrade to version 12.3.2 or later to receive a patch. As there are no known workarounds aside from upgrading, it is essential to apply this update to mitigate the issue.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-21670
GHSA-6VFC-QV3F-VR6C

Affected Products

Markdown-It