QID 983178
QID 983178: Nodejs (npm) Security Update for marked (GHSA-x5pg-88wf-qq4p)
Affected versions of `marked` are vulnerable to a regular expression denial of service.
The amplification in this vulnerability is significant, with 1,000 characters resulting in the event loop being blocked for around 6 seconds.
## Recommendation
Update to version 0.3.9 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-x5pg-88wf-qq4p for updates pertaining to this vulnerability.
Vendor References
- GHSA-x5pg-88wf-qq4p -
github.com/advisories/GHSA-x5pg-88wf-qq4p
CVEs related to QID 983178
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-x5pg-88wf-qq4p | marked |
|