5
CVSSv2

CVE-2021-21306

Published: 08/02/2021 Updated: 11/02/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before version 2.0.0, there is a Regular expression Denial of Service vulnerability. This vulnerability can affect anyone who runs user generated code through marked. This vulnerability is fixed in version 2.0.0.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

marked project marked

Vendor Advisories

In marked from version 111 and before version 200, there is a Regular expression Denial of Service vulnerability This vulnerability can affect anyone who runs user generated code through marked This vulnerability is fixed in version 200 ...