{"id":"GHSA-636f-xm5j-pj9m","summary":"Several quadratic complexity bugs may lead to denial of service in Commonmarker","details":"## Impact\n\nSeveral quadratic complexity bugs in commonmarker's underlying [`cmark-gfm`](https://github.com/github/cmark-gfm) library may lead to unbounded resource exhaustion and subsequent denial of service.\n\nThe following vulnerabilities were addressed:\n\n* [CVE-2023-22483](https://github.com/github/cmark-gfm/security/advisories/GHSA-29g3-96g3-jg6c)\n* [CVE-2023-22484](https://github.com/github/cmark-gfm/security/advisories/GHSA-24f7-9frr-5h2r)\n* [CVE-2023-22485](https://github.com/github/cmark-gfm/security/advisories/GHSA-c944-cv5f-hpvr)\n* [CVE-2023-22486](https://github.com/github/cmark-gfm/security/advisories/GHSA-r572-jvj2-3m8p)\n\nFor more information, consult the release notes for version [`0.23.0.gfm.7`](https://github.com/github/cmark-gfm/releases/tag/0.29.0.gfm.7).\n\n## Mitigation\n\nUsers are advised to upgrade to commonmarker version [`0.23.7`](https://rubygems.org/gems/commonmarker/versions/0.23.7).","modified":"2024-12-05T05:38:58.554988Z","published":"2023-01-24T18:12:17Z","database_specific":{"github_reviewed_at":"2023-01-24T18:12:17Z","nvd_published_at":null,"cwe_ids":["CWE-400"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/gjtorikian/commonmarker/security/advisories/GHSA-636f-xm5j-pj9m"},{"type":"PACKAGE","url":"https://github.com/gjtorikian/commonmarker"}],"affected":[{"package":{"name":"commonmarker","ecosystem":"RubyGems","purl":"pkg:gem/commonmarker"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.23.7"}]}],"versions":["0.0.1","0.1.0","0.1.1","0.1.2","0.1.3","0.10.0","0.11.0","0.12.0","0.13.0","0.14.0","0.14.1","0.14.11","0.14.12","0.14.13","0.14.14","0.14.15","0.14.2","0.14.3","0.14.4","0.14.5","0.14.6","0.14.7","0.14.8","0.14.9","0.15.0","0.16.0","0.16.1","0.16.2","0.16.3","0.16.4","0.16.5","0.16.6","0.16.7","0.16.8","0.17.0","0.17.1","0.17.10","0.17.11","0.17.12","0.17.13","0.17.2","0.17.4","0.17.5","0.17.6","0.17.7","0.17.7.1","0.17.8","0.17.9","0.18.0","0.18.1","0.18.2","0.19.0","0.2.0","0.2.1","0.20.0","0.20.1","0.20.2","0.21.0","0.21.1","0.21.2","0.22.0","0.23.0","0.23.1","0.23.2","0.23.4","0.23.5","0.23.6","0.23.7.pre1","0.3.0","0.4.0","0.4.1","0.5.0","0.5.1","0.6.0","0.7.0","0.8.0","0.9.0","0.9.1","0.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-636f-xm5j-pj9m/GHSA-636f-xm5j-pj9m.json"}}],"schema_version":"1.9.0"}