cbcvebase.
CVE-2017-17461
published 2018-01-04

CVE-2017-17461: Moderate severity vulnerability that affects marked # Withdrawn This advisory has been withdrawn, per NVD: ["This candidate was withdrawn by its CNA. Further…

medium
Moderate severity vulnerability that affects marked

# Withdrawn

This advisory has been withdrawn, per NVD: ["This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue."](https://nvd.nist.gov/vuln/detail/CVE-2017-17461)

# Original Description

A Regular expression Denial of Service (ReDoS) vulnerability in the file marked.js of the marked npm package (tested on version 0.3.7) allows a remote attacker to overload and crash a server by passing a maliciously crafted string.

Affected

1 ranges
VendorProductVersion rangeFixed in
marked_projectmarked>= 0 < 0.3.90.3.9
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.