Bug 2175704 (CVE-2023-26303) - CVE-2023-26303 markdown-it-py: Denial of service by forcing null assertions with specially crafted input
Summary: CVE-2023-26303 markdown-it-py: Denial of service by forcing null assertions w...
Keywords:
Status: NEW
Alias: CVE-2023-26303
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2175706 2175705
Blocks: Embargoed2172788
TreeView+ depends on / blocked
 
Reported: 2023-03-06 11:33 UTC by Vipul Nair
Modified: 2023-05-02 17:18 UTC (History)
19 users (show)

Fixed In Version: markdown-it-py 2.2.0
Doc Type: If docs needed, set a value
Doc Text:
A denial of service vulnerability exists in markdown-it-py.An attacker could craft a payload with null assertations as input resulting in a crash and availability of the component
Clone Of:
Environment:
Last Closed:


Attachments (Terms of Use)

Description Vipul Nair 2023-03-06 11:33:54 UTC
CVE-2023-26303
Denial of service could be caused to markdown-it-py, before v2.2.0, if an attacker was allowed to force null assertions with specially crafted input.

https://github.com/executablebooks/markdown-it-py/commit/ae03c6107dfa18e648f6fdd1280f5b89092d5d49

Comment 1 Vipul Nair 2023-03-06 11:36:05 UTC
Created ansible-lint tracking bugs for this issue:

Affects: fedora-all [bug 2175705]


Created python-ansible-compat tracking bugs for this issue:

Affects: fedora-all [bug 2175706]


Note You need to log in before you can comment on or make changes to this bug.