This repository has been archived by the owner on Mar 11, 2024. It is now read-only.
WS-2022-0093 (High) detected in commonmarker-0.17.7.1.gem #28
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
WS-2022-0093 - High Severity Vulnerability
Vulnerable Library - commonmarker-0.17.7.1.gem
A fast, safe, extensible parser for CommonMark. This wraps the official libcmark library.
Library home page: https://rubygems.org/gems/commonmarker-0.17.7.1.gem
Dependency Hierarchy:
Found in base branch: master
Vulnerability Details
commonmarker versions prior to 0.23.4 are vulnerable to heap memory corruption when parsing tables whose marker rows contain more than UINT16_MAX columns.
The impact of this heap corruption ranges from Information Leak to Arbitrary Code Execution.
Publish Date: 2022-02-03
URL: WS-2022-0093
CVSS 3 Score Details (8.8)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-fmx4-26r3-wxpf
Release Date: 2022-02-03
Fix Resolution: commonmarker - 0.23.4
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: