14.1.0
8 years ago
9 months ago
Known vulnerabilities in the org.webjars.npm:markdown-it package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
org.webjars.npm:markdown-it is a modern pluggable markdown parser. Affected versions of this package are vulnerable to Infinite loop in linkify inline rule when using malformed input. How to fix Infinite loop? Upgrade | [,14.1.0) |
org.webjars.npm:markdown-it is a modern pluggable markdown parser. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) via the How to fix Regular Expression Denial of Service (ReDoS)? Upgrade | [,12.3.2) |
org.webjars.npm:markdown-it is a modern pluggable markdown parser. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS). Parsing _*… takes quadratic time, this could be a denial of service vulnerability in an application that parses user input. How to fix Regular Expression Denial of Service (ReDoS)? Upgrade | [,10.0.0) |