{"id":"GHSA-636f-xm5j-pj9m","aliases":[],"url":"https://o3.security/vulnerability/GHSA-636f-xm5j-pj9m","summary":"Several quadratic complexity bugs may lead to denial of service in Commonmarker","details":"## Impact\n\nSeveral quadratic complexity bugs in commonmarker's underlying [`cmark-gfm`](https://github.com/github/cmark-gfm) library may lead to unbounded resource exhaustion and subsequent denial of service.\n\nThe following vulnerabilities were addressed:\n\n* [CVE-2023-22483](https://github.com/github/cmark-gfm/security/advisories/GHSA-29g3-96g3-jg6c)\n* [CVE-2023-22484](https://github.com/github/cmark-gfm/security/advisories/GHSA-24f7-9frr-5h2r)\n* [CVE-2023-22485](https://github.com/github/cmark-gfm/security/advisories/GHSA-c944-cv5f-hpvr)\n* [CVE-2023-22486](https://github.com/github/cmark-gfm/security/advisories/GHSA-r572-jvj2-3m8p)\n\nFor more information, consult the release notes for version [`0.23.0.gfm.7`](https://github.com/github/cmark-gfm/releases/tag/0.29.0.gfm.7).\n\n## Mitigation\n\nUsers are advised to upgrade to commonmarker version [`0.23.7`](https://rubygems.org/gems/commonmarker/versions/0.23.7).","published":"2023-01-24T18:12:17Z","modified":"2024-12-05T05:38:58.554988Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"commonmarker","fixedVersion":"0.23.7"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/gjtorikian/commonmarker/security/advisories/GHSA-636f-xm5j-pj9m"},{"type":"PACKAGE","url":"https://github.com/gjtorikian/commonmarker"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-05T05:38:58.554988Z"}}