Skip to content
This repository has been archived by the owner on Mar 11, 2024. It is now read-only.

WS-2023-0095 (High) detected in commonmarker-0.17.7.1.gem #47

Open
mend-bolt-for-github bot opened this issue Apr 15, 2023 · 0 comments
Open

WS-2023-0095 (High) detected in commonmarker-0.17.7.1.gem #47

mend-bolt-for-github bot opened this issue Apr 15, 2023 · 0 comments
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource

Comments

@mend-bolt-for-github
Copy link
Contributor

mend-bolt-for-github bot commented Apr 15, 2023

WS-2023-0095 - High Severity Vulnerability

Vulnerable Library - commonmarker-0.17.7.1.gem

A fast, safe, extensible parser for CommonMark. This wraps the official libcmark library.

Library home page: https://rubygems.org/gems/commonmarker-0.17.7.1.gem

Dependency Hierarchy:

  • github-pages-175.gem (Root Library)
    • jekyll-commonmark-ghpages-0.1.3.gem
      • commonmarker-0.17.7.1.gem (Vulnerable Library)

Found in base branch: master

Vulnerability Details

Commonmarker vulnerable to to several quadratic complexity bugs that may lead to denial of service

Publish Date: 2023-04-12

URL: WS-2023-0095

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-48wp-p9qv-4j64

Release Date: 2023-04-12

Fix Resolution: commonmarker - 0.23.9


Step up your Open Source Security Game with Mend here

@mend-bolt-for-github mend-bolt-for-github bot added the Mend: dependency security vulnerability Security vulnerability detected by WhiteSource label Apr 15, 2023
@mend-bolt-for-github mend-bolt-for-github bot changed the title WS-2023-0095 (Medium) detected in commonmarker-0.17.7.1.gem WS-2023-0095 (High) detected in commonmarker-0.17.7.1.gem May 31, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource
Projects
None yet
Development

No branches or pull requests

0 participants