GHSA-636f-xm5j-pj9m

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-636f-xm5j-pj9m/GHSA-636f-xm5j-pj9m.json
Published
2023-01-24T18:12:17Z
Modified
2023-01-31T02:34:23.859269Z
Details

Impact

Several quadratic complexity bugs in commonmarker's underlying cmark-gfm library may lead to unbounded resource exhaustion and subsequent denial of service.

The following vulnerabilities were addressed:

For more information, consult the release notes for version 0.23.0.gfm.7.

Mitigation

Users are advised to upgrade to commonmarker version 0.23.7.

References

Affected packages

RubyGems / commonmarker

commonmarker

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0
Fixed
0.23.7

Affected versions

0.*

0.0.1
0.1.0
0.1.1
0.1.2
0.1.3
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.14.1
0.14.11
0.14.12
0.14.13
0.14.14
0.14.15
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.2
0.17.4
0.17.5
0.17.6
0.17.7
0.17.7.1
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.19.0
0.2.0
0.2.1
0.20.0
0.20.1
0.20.2
0.21.0
0.21.1
0.21.2
0.22.0
0.23.0
0.23.1
0.23.2
0.23.4
0.23.5
0.23.6
0.23.7.pre1
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
0.9.2