VDB
Sign up
MEDIUM

GHSA-7vh7-fw88-wj87

Several quadratic complexity bugs may lead to denial of service in Commonmarker

Quick fix

GHSA-7vh7-fw88-wj87 — commonmarker: upgrade to the fixed version with the command below.

bundle update commonmarker

Details

## Impact

Several quadratic complexity bugs in commonmarker's underlying [`cmark-gfm`](https://github.com/github/cmark-gfm) library may lead to unbounded resource exhaustion and subsequent denial of service.

The following vulnerabilities were addressed:

* [CVE-2023-37463](https://github.com/github/cmark-gfm/security/advisories/GHSA-w4qg-3vf7-m9x5)

For more information, consult the release notes for version [`0.29.0.gfm.12`](https://github.com/github/cmark-gfm/releases/tag/0.29.0.gfm.12).

## Mitigation

Users are advised to upgrade to commonmarker version [`0.23.10`](https://rubygems.org/gems/commonmarker/versions/0.23.10).

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/commonmarker
Introduced in: 0Fixed in: 0.23.10
Fixbundle update commonmarker

References