Dismissed
Permalink
CVE-2023-26303
3.3 LOW
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): NONE
- Availability impact (A): LOW
by @LeSuisse Activity log
- Created automatic suggestion
- @LeSuisse dismissed
markdown-it-py crash on null assertions
Denial of service could be caused to markdown-it-py, before v2.2.0, if an attacker was allowed to force null assertions with specially crafted input.
References
Affected products
markdown-it-py
- <v2.2.0
Matching in nixpkgs
pkgs.python311Packages.markdown-it-py
Markdown parser in Python
pkgs.python312Packages.markdown-it-py
Markdown parser in Python
Package maintainers
-
@bhipple Benjamin Hipple <bhipple@protonmail.com>