markdown-it < 1.3.2 - Uncontrolled Resource Consumption
2022-01-10 00:00
AnonymousStrategic Overview
StatusPatched in 1.1.0
Affected PluginBlock for Apple Maps
Affected Version
1.0.3CVSS5.3Medium
CVE
CVE-2022-21670Vulnerability Overview
The package markdown-it 1.3.2 is vulnerable to Uncontrolled Resource Consumption in cases where special patterns with length greater than 50 thousand characters are used. As this package is used in some WordPress plugins, this could result in the impacted plugins being vulnerable.
Technical Analysis
REMEDIATION: Update to version 1.1.0, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C