GHSA-7m7q-q53v-j47v

Suggest an improvement
Source
https://github.com/advisories/GHSA-7m7q-q53v-j47v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-7m7q-q53v-j47v/GHSA-7m7q-q53v-j47v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7m7q-q53v-j47v
Withdrawn
2021-02-25T02:01:47Z
Published
2021-02-25T02:01:47Z
Modified
2021-02-25T02:01:47Z
Summary
Regular Expression Denial of Service
Details

A flaw was found in nodejs-marked versions from 0.5.0 to before 0.6.1. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS). Input to the host variable is vulnerable when input contains parenthesis in link URIs, coupled with a high number of link tokens in a single line.

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2019-06-04T19:45:00Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / marked

Package

Affected ranges

Type
SEMVER
Events
Introduced
0.5.0
Fixed
0.6.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-7m7q-q53v-j47v/GHSA-7m7q-q53v-j47v.json"