GHSA-7vh7-fw88-wj87
Several quadratic complexity bugs may lead to denial of service in Commonmarker
Quick fix
GHSA-7vh7-fw88-wj87 — commonmarker: upgrade to the fixed version with the command below.
bundle update commonmarkerDetails
## Impact
Several quadratic complexity bugs in commonmarker's underlying [`cmark-gfm`](https://github.com/github/cmark-gfm) library may lead to unbounded resource exhaustion and subsequent denial of service.
The following vulnerabilities were addressed:
* [CVE-2023-37463](https://github.com/github/cmark-gfm/security/advisories/GHSA-w4qg-3vf7-m9x5)
For more information, consult the release notes for version [`0.29.0.gfm.12`](https://github.com/github/cmark-gfm/releases/tag/0.29.0.gfm.12).
## Mitigation
Users are advised to upgrade to commonmarker version [`0.23.10`](https://rubygems.org/gems/commonmarker/versions/0.23.10).
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/gjtorikian/commonmarker/security/advisories/GHSA-7vh7-fw88-wj87[WEB]
- https://github.com/gjtorikian/commonmarker/commit/db8cd377b54541f7fd484d168b7682a282a680f7[WEB]
- https://github.com/github/cmark-gfm/releases/tag/0.29.0.gfm.12[WEB]
- https://github.com/gjtorikian/commonmarker[PACKAGE]
- https://rubygems.org/gems/commonmarker/versions/0.23.10[WEB]