8.4.1
9 years ago
6 years ago
Known vulnerabilities in the org.webjars.bower:markdown-it package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
org.webjars.bower:markdown-it is a modern pluggable markdown parser. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) via the How to fix Regular Expression Denial of Service (ReDoS)? There is no fixed version for | [0,) |
org.webjars.bower:markdown-it is a modern pluggable markdown parser. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS). Parsing _*… takes quadratic time, this could be a denial of service vulnerability in an application that parses user input. How to fix Regular Expression Denial of Service (ReDoS)? There is no fixed version for | [0,) |
Affected versions of the package are vulnerable to Cross-site Scripting (XSS) via Class Injection. The markdown-it renderer blindly appends the character class to the
will be rendered into
A malicious user can attach an arbitrary class to the How to fix Cross-site Scripting (XSS)? Upgrade | [4.0.0,4.3.1) |