VDB
Sign up
MEDIUM

GHSA-636f-xm5j-pj9m

Several quadratic complexity bugs may lead to denial of service in Commonmarker

Quick fix

GHSA-636f-xm5j-pj9m — commonmarker: upgrade to the fixed version with the command below.

bundle update commonmarker

Details

## Impact

Several quadratic complexity bugs in commonmarker's underlying [`cmark-gfm`](https://github.com/github/cmark-gfm) library may lead to unbounded resource exhaustion and subsequent denial of service.

The following vulnerabilities were addressed:

* [CVE-2023-22483](https://github.com/github/cmark-gfm/security/advisories/GHSA-29g3-96g3-jg6c) * [CVE-2023-22484](https://github.com/github/cmark-gfm/security/advisories/GHSA-24f7-9frr-5h2r) * [CVE-2023-22485](https://github.com/github/cmark-gfm/security/advisories/GHSA-c944-cv5f-hpvr) * [CVE-2023-22486](https://github.com/github/cmark-gfm/security/advisories/GHSA-r572-jvj2-3m8p)

For more information, consult the release notes for version [`0.23.0.gfm.7`](https://github.com/github/cmark-gfm/releases/tag/0.29.0.gfm.7).

## Mitigation

Users are advised to upgrade to commonmarker version [`0.23.7`](https://rubygems.org/gems/commonmarker/versions/0.23.7).

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/commonmarker
Introduced in: 0Fixed in: 0.23.7
Fixbundle update commonmarker

References