CVE-2021-21306
published 2021-02-08CVE-2021-21306: Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before version 2.0.0, there is a Regular…
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.46%
82.8th percentile
Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before version 2.0.0, there is a Regular expression Denial of Service vulnerability. This vulnerability can affect anyone who runs user generated code through marked. This vulnerability is fixed in version 2.0.0.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-marked | — | — |
| marked_project | marked | >= 1.1.1 < 2.0.0 | 2.0.0 |
| marked_project | marked | >= 1.1.1 < 2.0.0 | 2.0.0 |
| markedjs | marked | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Regular Expression Denial of Service (REDoS) in Marked
ghsa·2021-02-08
CVE-2021-21306 [MEDIUM] CWE-400 Regular Expression Denial of Service (REDoS) in Marked
Regular Expression Denial of Service (REDoS) in Marked
### Impact
_What kind of vulnerability is it? Who is impacted?_
[Regular expression Denial of Service](https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS)
A Denial of Service attack can affect anyone who runs user generated code through `marked`.
### Patches
_Has the problem been patched? What versions should users upgrade to?_
patched in v2.0.0
### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_
None.
### References
_Are there any links users can visit to find out more?_
https://github.com/markedjs/marked/issues/1927
https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS
### For more information
If you have any que
OSV
Regular Expression Denial of Service (REDoS) in Marked
osv·2021-02-08
CVE-2021-21306 [MEDIUM] Regular Expression Denial of Service (REDoS) in Marked
Regular Expression Denial of Service (REDoS) in Marked
### Impact
_What kind of vulnerability is it? Who is impacted?_
[Regular expression Denial of Service](https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS)
A Denial of Service attack can affect anyone who runs user generated code through `marked`.
### Patches
_Has the problem been patched? What versions should users upgrade to?_
patched in v2.0.0
### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_
None.
### References
_Are there any links users can visit to find out more?_
https://github.com/markedjs/marked/issues/1927
https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS
### For more information
If you have any que
Red Hat
nodejs-marked: Regular expression denial of service
vendor_redhat·2021-02-08·CVSS 5.3
CVE-2021-21306 [MEDIUM] CWE-400 nodejs-marked: Regular expression denial of service
nodejs-marked: Regular expression denial of service
Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before version 2.0.0, there is a Regular expression Denial of Service vulnerability. This vulnerability can affect anyone who runs user generated code through marked. This vulnerability is fixed in version 2.0.0.
Package: servicemesh-grafana (OpenShift Service Mesh 2.0) - Not affected
Package: openshift4/ose-grafana (Red Hat OpenShift Container Platform 4) - Not affected
Debian
CVE-2021-21306: node-marked - Marked is an open-source markdown parser and compiler (npm package "marked"). In...
vendor_debian·2021·CVSS 5.3
CVE-2021-21306 [MEDIUM] CVE-2021-21306: node-marked - Marked is an open-source markdown parser and compiler (npm package "marked"). In...
Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before version 2.0.0, there is a Regular expression Denial of Service vulnerability. This vulnerability can affect anyone who runs user generated code through marked. This vulnerability is fixed in version 2.0.0.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/markedjs/marked/commit/7293251c438e3ee968970f7609f1a27f9007bccdhttps://github.com/markedjs/marked/issues/1927https://github.com/markedjs/marked/pull/1864https://github.com/markedjs/marked/security/advisories/GHSA-4r62-v4vq-hr96https://www.npmjs.com/package/markedhttps://github.com/markedjs/marked/commit/7293251c438e3ee968970f7609f1a27f9007bccdhttps://github.com/markedjs/marked/issues/1927https://github.com/markedjs/marked/pull/1864https://github.com/markedjs/marked/security/advisories/GHSA-4r62-v4vq-hr96https://www.npmjs.com/package/marked
2021-02-08
Published