Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Marker decency package has been marked as Moderate vulnerability by npm audit #14

Closed
balab2020 opened this issue Apr 26, 2019 · 2 comments · Fixed by #15
Closed

Marker decency package has been marked as Moderate vulnerability by npm audit #14

balab2020 opened this issue Apr 26, 2019 · 2 comments · Fixed by #15
Labels

Comments

@balab2020
Copy link

balab2020 commented Apr 26, 2019

Moderate Regular Expression Denial of Service

Module: marked
Published: April 10th 2019
Reported by: Anders Kaseorg
CWE-400
Vulnerable: >=0.3.14 <0.6.2
Patched: >=0.6.2
CVSS: 5
Overview
Versions of marked prior to 0.6.2 and later than 0.3.14 are vulnerable to Regular Expression Denial of Service. Email addresses may be evaluated in quadratic time, allowing attackers to potentially crash the node process due to resource exhaustion.

Findings
npm-audit-html>marked
Remediation : Upgrade to version 0.6.2 or later.

References
GitHub PR (markedjs/marked#1460)
Snyk Report (https://snyk.io/vuln/SNYK-JS-MARKED-174116)

@nprail
Copy link
Member

nprail commented Apr 26, 2019

🎉 This issue has been resolved in version 1.3.2 🎉

The release is available on:

Your semantic-release bot 📦🚀

@nprail
Copy link
Member

nprail commented Jul 26, 2019

🎉 This issue has been resolved in version 1.3.3 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants