QID 983499
QID 983499: Nodejs (npm) Security Update for marked (GHSA-crmx-v835-hcp4)
A Regular expression Denial of Service (ReDoS) vulnerability in the file marked.js of the marked npm package (tested on version 0.3.7) allows a remote attacker to overload and crash a server by passing a maliciously crafted string.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-crmx-v835-hcp4 for updates pertaining to this vulnerability.
Vendor References
- GHSA-crmx-v835-hcp4 -
github.com/advisories/GHSA-crmx-v835-hcp4
CVEs related to QID 983499
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-crmx-v835-hcp4 | marked |
|