CVE-2015-8854

high
Published 2017-01-23 · Modified 2024-02-09
CVSS v3
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
VIR risk
7.5

Description

The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecified vectors that trigger a "catastrophic backtracking issue for the em inline rule," aka a "regular expression denial of service (ReDoS)."

Predictions

Exploit likelihood
83%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0.3.6+dfsg-1
debian debianbullseyefixed0.3.6+dfsg-1
debian debianforkyfixed0.3.6+dfsg-1
debian debiansidfixed0.3.6+dfsg-1
debian debiantrixiefixed0.3.6+dfsg-1
fedora fedora31affected
fedora fedora32affected

Package impact

EcosystemPackageVulnerableFixed
npm npmmarked<0.3.40.3.4

Application impact

VendorProductVersionsFixed
marked_projectmarked{"endExcluding":"0.3.4"}0.3.4

References

CWEs

CWE-1333

💬 Discuss CVE-2015-8854 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.