ADVISORIES
GEM
PATCHED VERSIONS
- >= 0.23.10
DESCRIPTION
Impact
Several quadratic complexity bugs in commonmarker's underlying
cmark-gfm
library may
lead to unbounded resource exhaustion and subsequent denial of service.
The following vulnerabilities were addressed:
For more information, consult the release notes for version
0.29.0.gfm.12
.
Mitigation
Users are advised to upgrade to commonmarker version
0.23.10
.
RELATED
- https://github.com/gjtorikian/commonmarker/security/advisories/GHSA-7vh7-fw88-wj87
- https://github.com/github/cmark-gfm/releases/tag/0.29.0.gfm.12
- https://github.com/gjtorikian/commonmarker/commit/db8cd377b54541f7fd484d168b7682a282a680f7
- https://github.com/github/cmark-gfm/security/advisories/GHSA-w4qg-3vf7-m9x5
- https://rubygems.org/gems/commonmarker/versions/0.23.10
- https://github.com/advisories/GHSA-7vh7-fw88-wj87