markdown-it < 1.3.2 - Uncontrolled Resource Consumption

2022-01-10 00:00
Anonymous

Strategic Overview

Status
Patched in 1.1.0
Affected PluginBlock for Apple Maps
Affected Version1.0.3
CVSS5.3Medium
CVECVE-2022-21670
View all Block for Apple Maps vulnerabilities

Vulnerability Overview

The package markdown-it 1.3.2 is vulnerable to Uncontrolled Resource Consumption in cases where special patterns with length greater than 50 thousand characters are used. As this package is used in some WordPress plugins, this could result in the impacted plugins being vulnerable.

Technical Analysis

REMEDIATION: Update to version 1.1.0, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C