This repository has been archived by the owner on Apr 29, 2020. It is now read-only.
WS-2019-0209 (Medium) detected in marked-0.2.9.js, marked-0.3.19.js #132
Labels
security vulnerability
Security vulnerability detected by WhiteSource
WS-2019-0209 - Medium Severity Vulnerability
Vulnerable Libraries - marked-0.2.9.js, marked-0.3.19.js
marked-0.2.9.js
A markdown parser built for speed
Library home page: https://cdnjs.cloudflare.com/ajax/libs/marked/0.2.9/marked.js
Path to vulnerable library: /Notabene/lib/angular-moment-master/node_modules/grunt-ngdocs/src/templates/js/marked.js
Dependency Hierarchy:
marked-0.3.19.js
A markdown parser built for speed
Library home page: https://cdnjs.cloudflare.com/ajax/libs/marked/0.3.19/marked.js
Path to vulnerable library: /Notabene/lib/angular-moment-master/node_modules/marked/lib/marked.js
Dependency Hierarchy:
Found in HEAD commit: 4116360a86baf39eef28676502817c4c42e489e6
Vulnerability Details
marked before 0.7.0 vulnerable to Redos attack by he _label subrule that may significantly degrade parsing performance of malformed input.
Publish Date: 2019-09-05
URL: WS-2019-0209
CVSS 2 Score Details (5.0)
Base Score Metrics not available
Suggested Fix
Type: Upgrade version
Origin: https://www.npmjs.com/advisories/1076
Release Date: 2019-09-05
Fix Resolution: 0.7.0
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: