Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before version 2.0.0, there is a Regular expression Denial of Service vulnerability. This vulnerability can affect anyone who runs user generated code through marked. This vulnerability is fixed in version 2.0.0.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0532 | Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before version 2.0.0, there is a Regular expression Denial of Service vulnerability. This vulnerability can affect anyone who runs user generated code through marked. This vulnerability is fixed in version 2.0.0. |
Github GHSA |
GHSA-4r62-v4vq-hr96 | Regular Expression Denial of Service (REDoS) in Marked |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-03T18:09:15.882Z
Reserved: 2020-12-22T00:00:00.000Z
Link: CVE-2021-21306
No data.
Status : Modified
Published: 2021-02-08T22:15:12.450
Modified: 2024-11-21T05:47:59.210
Link: CVE-2021-21306
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA