QID 997044
Date Published: 2024-02-01
QID 997044: NodeJs (Npm) Security Update for mathjax (GHSA-v638-q856-grg8)
Mathjax up to v2.7.9 was discovered to contain two Regular expression Denial of Service (ReDoS) vulnerabilities in MathJax.js via the components pattern and markdownPattern. NOTE: the vendor disputes this because the regular expressions are not applied to user input; thus, there is no risk.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-v638-q856-grg8 for updates and patch information.
Vendor References
- GHSA-v638-q856-grg8 -
github.com/advisories/GHSA-v638-q856-grg8
CVEs related to QID 997044
Software Advisories
| Advisory ID | Software | Component | Link |
|---|