VulnerabilityModified
CVE-2024-22051
CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability.
CRITICAL 9.8EPSS 1.45%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.45%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.45% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- github/cmark-gfm · gjtorikian/commonmarker
- Source
- disclosure@vulncheck.com
References
- https://github.com/advisories/GHSA-fmx4-26r3-wxpfThird Party Advisory
- https://github.com/github/cmark-gfm/security/advisories/GHSA-mc3g-88wq-6f4xNot Applicable
- https://github.com/gjtorikian/commonmarker/commit/ab4504fd17460627a6ab255bc3c63e8e5fc6aed3Patch
- https://github.com/gjtorikian/commonmarker/security/advisories/GHSA-fmx4-26r3-wxpfVendor Advisory
- https://vulncheck.com/advisories/vc-advisory-GHSA-fmx4-26r3-wxpfThird Party Advisory
- https://github.com/advisories/GHSA-fmx4-26r3-wxpfThird Party Advisory
- https://github.com/github/cmark-gfm/security/advisories/GHSA-mc3g-88wq-6f4xNot Applicable
- https://github.com/gjtorikian/commonmarker/commit/ab4504fd17460627a6ab255bc3c63e8e5fc6aed3Patch
- https://github.com/gjtorikian/commonmarker/security/advisories/GHSA-fmx4-26r3-wxpfVendor Advisory
- https://vulncheck.com/advisories/vc-advisory-GHSA-fmx4-26r3-wxpfThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.