Review reviewCritical

CVE-2024-22051

github cmark-gfm, commonmarker

CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.

CVSS
9.8
EPSS
1.45%
70.8% percentile
CISA KEV
Not listed
Published
2024.01.05
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability1.45%
Technical severityCVSS 9.8

Vulnerability overview

CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.

Affected product and versions

Product
github cmark-gfm, commonmarker
Affected versions
< 0.23.4, < 0.28.3.gfm.21, >= 0.29.0.gfm.0 < 0.29.0.gfm.3
Fixed versions
0.28.3.gfm.21, 0.29.0.gfm.3, 0.23.4

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that github cmark-gfm, commonmarker and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-190
CVE-2024-22051 — github cmark-gfm, commonmarker | SECUFOCUS NOW