// For flags

CVE-2024-22051

CommonMarker Integer Overflow Vulnerability

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.

Las versiones de CommonMarker anteriores a la 0.23.4 corren el riesgo de sufrir una vulnerabilidad de desbordamiento de enteros. Esta vulnerabilidad puede provocar que atacantes remotos posiblemente no autenticados provoquen daños en la memoria del montón, lo que podría provocar una fuga de información o la ejecución remota de código, a través de tablas de análisis con filas de marcadores que contienen más de columnas UINT16_MAX.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2024-01-04 CVE Reserved
  • 2024-01-04 CVE Published
  • 2024-01-18 EPSS Updated
  • 2024-08-01 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-190: Integer Overflow or Wraparound
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Github
Search vendor "Github"
Cmark-gfm
Search vendor "Github" for product "Cmark-gfm"
< 0.28.3.gfm.21
Search vendor "Github" for product "Cmark-gfm" and version " < 0.28.3.gfm.21"
-
Affected
Github
Search vendor "Github"
Cmark-gfm
Search vendor "Github" for product "Cmark-gfm"
>= 0.29.0.gfm.0 < 0.29.0.gfm.3
Search vendor "Github" for product "Cmark-gfm" and version " >= 0.29.0.gfm.0 < 0.29.0.gfm.3"
-
Affected
Gjtorikian
Search vendor "Gjtorikian"
Commonmarker
Search vendor "Gjtorikian" for product "Commonmarker"
< 0.23.4
Search vendor "Gjtorikian" for product "Commonmarker" and version " < 0.23.4"
ruby
Affected