-
Type: Bug
-
Status: Open
-
Priority: Minor
-
Resolution: Unresolved
-
Affects Version/s: None
-
Fix Version/s: None
-
Component/s: Web UI
-
Tags:
-
Sprint:UI COOLDOWN - 2024-11
SRCCLR-SID-6127 | Unknown
Severity : Medium
marked is vulnerable to regular expression denial-of-service (ReDoS) attacks. The vulnerability exists as a vulnerable regex for parsing `heading` causes catastrophic backtracking is used in `lib/marked.js`, allowing a malicious input to consume resources to cause a ReDoS attack.
Module : marked
nuxeo-web-ui.zip#zip:node_modules:marked
Current Version : 0.3.19
Recommended version to upgrade : 12.0.2 ( Latest )
- clones
-
WEBUI-1523 [MARKED] SRCCLR-SID-6274 | Unknown
- In Review
- is cloned by
-
WEBUI-1525 [MARKED] SRCCLR-SID-13630 | Unknown
- Open