Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Exponential ReDoS in markdown-link-extractor
Vulnerability Description
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package, when an attacker is able to supply arbitrary input to the module's exported function
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
CWE-1333
Vulnerability Title
npm markdown-link-extractor 安全漏洞
Vulnerability Description
npm markdown-link-extractor是美国npm公司的用于从 Markdown 文本中提取链接。 npm markdown-link-extractor 3.0.1 和 4.0.0 版本存在安全漏洞,攻击者利用该漏洞可向模块的导出函数提供任意输入时触发指数 ReDoS(正则表达式拒绝服务)。
CVSS Information
N/A
Vulnerability Type
N/A