CVE-2022-21680
published 2022-01-14CVE-2022-21680: Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against some strings…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.83%
85.0th percentile
Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against some strings and lead to a regular expression denial of service (ReDoS). Anyone who runs untrusted markdown through a vulnerable version of marked and does not use a worker with a time limit may be affected. This issue is patched in version 4.0.10. As a workaround, avoid running untrusted markdown through marked or run marked on a worker thread and set a reasonable time limit to prevent draining resources.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-marked | < node-marked 4.0.12+ds+~4.0.1-1 (bookworm) | node-marked 4.0.12+ds+~4.0.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| marked_project | marked | < 4.0.10 | 4.0.10 |
| marked_project | marked | >= 0 < 4.0.10 | 4.0.10 |
| markedjs | marked | < 4.0.10 | 4.0.10 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Inefficient Regular Expression Complexity in marked
osv·2022-01-14
CVE-2022-21680 [HIGH] Inefficient Regular Expression Complexity in marked
Inefficient Regular Expression Complexity in marked
### Impact
_What kind of vulnerability is it?_
Denial of service.
The regular expression `block.def` may cause catastrophic backtracking against some strings.
PoC is the following.
```javascript
import * as marked from "marked";
marked.parse(`[x]:${' '.repeat(1500)}x ${' '.repeat(1500)} x`);
```
_Who is impacted?_
Anyone who runs untrusted markdown through marked and does not use a worker with a time limit.
### Patches
_Has the problem been patched?_
Yes
_What versions should users upgrade to?_
4.0.10
### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_
Do not run untrusted markdown through marked or run marked on a [worker](https://marked.js.org/using_advanced#workers) thread
GHSA
Inefficient Regular Expression Complexity in marked
ghsa·2022-01-14
CVE-2022-21680 [HIGH] CWE-1333 Inefficient Regular Expression Complexity in marked
Inefficient Regular Expression Complexity in marked
### Impact
_What kind of vulnerability is it?_
Denial of service.
The regular expression `block.def` may cause catastrophic backtracking against some strings.
PoC is the following.
```javascript
import * as marked from "marked";
marked.parse(`[x]:${' '.repeat(1500)}x ${' '.repeat(1500)} x`);
```
_Who is impacted?_
Anyone who runs untrusted markdown through marked and does not use a worker with a time limit.
### Patches
_Has the problem been patched?_
Yes
_What versions should users upgrade to?_
4.0.10
### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_
Do not run untrusted markdown through marked or run marked on a [worker](https://marked.js.org/using_advanced#workers) thread
OSV
CVE-2022-21680: Marked is a markdown parser and compiler
osv·2022-01-14·CVSS 7.5
CVE-2022-21680 [HIGH] CVE-2022-21680: Marked is a markdown parser and compiler
Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against some strings and lead to a regular expression denial of service (ReDoS). Anyone who runs untrusted markdown through a vulnerable version of marked and does not use a worker with a time limit may be affected. This issue is patched in version 4.0.10. As a workaround, avoid running untrusted markdown through marked or run marked on a worker thread and set a reasonable time limit to prevent draining resources.
Red Hat
marked: regular expression block.def may lead Denial of Service
vendor_redhat·2022-01-14·CVSS 7.5
CVE-2022-21680 [HIGH] CWE-186 marked: regular expression block.def may lead Denial of Service
marked: regular expression block.def may lead Denial of Service
Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against some strings and lead to a regular expression denial of service (ReDoS). Anyone who runs untrusted markdown through a vulnerable version of marked and does not use a worker with a time limit may be affected. This issue is patched in version 4.0.10. As a workaround, avoid running untrusted markdown through marked or run marked on a worker thread and set a reasonable time limit to prevent draining resources.
A vulnerability was found in the markedjs package. Affected versions of this package are vulnerable to Regular expression Denial of Service (ReDoS) attacks, affecting system avai
Debian
CVE-2022-21680: node-marked - Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular e...
vendor_debian·2022·CVSS 7.5
CVE-2022-21680 [HIGH] CVE-2022-21680: node-marked - Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular e...
Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against some strings and lead to a regular expression denial of service (ReDoS). Anyone who runs untrusted markdown through a vulnerable version of marked and does not use a worker with a time limit may be affected. This issue is patched in version 4.0.10. As a workaround, avoid running untrusted markdown through marked or run marked on a worker thread and set a reasonable time limit to prevent draining resources.
Scope: local
bookworm: resolved (fixed in 4.0.12+ds+~4.0.1-1)
bullseye: open
forky: resolved (fixed in 4.0.12+ds+~4.0.1-1)
sid: resolved (fixed in 4.0.12+ds+~4.0.1-1)
trixie: resolved (fixed in 4.0.12+ds+~4.0.1-1)
No detection rules found.
No public exploits indexed.
https://github.com/markedjs/marked/commit/c4a3ccd344b6929afa8a1d50ac54a721e57012c0https://github.com/markedjs/marked/releases/tag/v4.0.10https://github.com/markedjs/marked/security/advisories/GHSA-rrrm-qjm4-v8hfhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AIXDMC3CSHYW3YWVSQOXAWLUYQHAO5UX/https://github.com/markedjs/marked/commit/c4a3ccd344b6929afa8a1d50ac54a721e57012c0https://github.com/markedjs/marked/releases/tag/v4.0.10https://github.com/markedjs/marked/security/advisories/GHSA-rrrm-qjm4-v8hfhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AIXDMC3CSHYW3YWVSQOXAWLUYQHAO5UX/
2022-01-14
Published