-
Type: Bug
-
Status: Open
-
Priority: Minor
-
Resolution: Unresolved
-
Affects Version/s: None
-
Fix Version/s: None
-
Component/s: Web UI
-
Tags:
-
Sprint:UI COOLDOWN - 2024-11
SRCCLR-SID-13630 | Unknown
Severity : Medium
marked is vulnerable to regular expression denial of service (ReDoS) attacks. The vulnerability exists as the `inline.text` regex could require a quadratic time to complete a scan, causing ReDoS.
Module : marked
nuxeo-web-ui.zip#zip:node_modules:marked
Current Version : 0.3.19
Recommended version to upgrade : 12.0.2 ( Latest )
- clones
-
WEBUI-1524 [MARKED] SRCCLR-SID-6127 | Unknown
- Open