Skip to content
This repository has been archived by the owner on Mar 11, 2024. It is now read-only.

WS-2022-0093 (High) detected in commonmarker-0.17.7.1.gem #28

Open
mend-bolt-for-github bot opened this issue Mar 8, 2022 · 0 comments
Open

WS-2022-0093 (High) detected in commonmarker-0.17.7.1.gem #28

mend-bolt-for-github bot opened this issue Mar 8, 2022 · 0 comments
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource

Comments

@mend-bolt-for-github
Copy link
Contributor

mend-bolt-for-github bot commented Mar 8, 2022

WS-2022-0093 - High Severity Vulnerability

Vulnerable Library - commonmarker-0.17.7.1.gem

A fast, safe, extensible parser for CommonMark. This wraps the official libcmark library.

Library home page: https://rubygems.org/gems/commonmarker-0.17.7.1.gem

Dependency Hierarchy:

  • github-pages-175.gem (Root Library)
    • jekyll-commonmark-ghpages-0.1.3.gem
      • commonmarker-0.17.7.1.gem (Vulnerable Library)

Found in base branch: master

Vulnerability Details

commonmarker versions prior to 0.23.4 are vulnerable to heap memory corruption when parsing tables whose marker rows contain more than UINT16_MAX columns.
The impact of this heap corruption ranges from Information Leak to Arbitrary Code Execution.

Publish Date: 2022-02-03

URL: WS-2022-0093

CVSS 3 Score Details (8.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-fmx4-26r3-wxpf

Release Date: 2022-02-03

Fix Resolution: commonmarker - 0.23.4


Step up your Open Source Security Game with Mend here

@mend-bolt-for-github mend-bolt-for-github bot added the Mend: dependency security vulnerability Security vulnerability detected by WhiteSource label Mar 8, 2022
@mend-bolt-for-github mend-bolt-for-github bot changed the title WS-2022-0093 (Medium) detected in commonmarker-0.17.7.1.gem WS-2022-0093 (High) detected in commonmarker-0.17.7.1.gem May 26, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource
Projects
None yet
Development

No branches or pull requests

0 participants