CVE-2022-21670

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-21670
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-21670.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-21670
Aliases
Related
Published
2022-01-10T21:15:07Z
Modified
2025-01-15T02:14:23.740901Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
[none]
Details

markdown-it is a Markdown parser. Prior to version 1.3.2, special patterns with length greater than 50 thousand characterss could slow down the parser significantly. Users should upgrade to version 12.3.2 to receive a patch. There are no known workarounds aside from upgrading.

References

Affected packages

Debian:11 / node-markdown-it

Package

Name
node-markdown-it
Purl
pkg:deb/debian/node-markdown-it?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.0.0+dfsg-2+deb11u1

Affected versions

10.*

10.0.0+dfsg-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / node-markdown-it

Package

Name
node-markdown-it
Purl
pkg:deb/debian/node-markdown-it?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.0.0+dfsg-6

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / node-markdown-it

Package

Name
node-markdown-it
Purl
pkg:deb/debian/node-markdown-it?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.0.0+dfsg-6

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/markdown-it/markdown-it

Affected ranges

Type
GIT
Repo
https://github.com/markdown-it/markdown-it
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

10.*

10.0.0

11.*

11.0.0
11.0.1

12.*

12.0.0
12.0.1
12.0.2
12.0.3
12.0.4
12.0.5
12.0.6
12.1.0
12.2.0
12.3.0
12.3.1

2.*

2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1

3.*

3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0

4.*

4.0.0
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.2.0
4.2.1
4.2.2
4.3.0
4.3.1
4.4.0

5.*

5.0.0
5.0.1
5.0.2
5.0.3
5.1.0

6.*

6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.1.0
6.1.1

7.*

7.0.0
7.0.1

8.*

8.0.0
8.0.1
8.1.0
8.2.0
8.2.1
8.2.2
8.3.0
8.3.1
8.3.2
8.4.0
8.4.1
8.4.2

9.*

9.0.0
9.0.1
9.1.0