« Volver al listado

CVE-2021-21306

Estado: ModificadaAlta (7.5)—

Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before version 2.0.0, there is a Regular expression Denial of Service vulnerability. This vulnerability can affect anyone who runs user generated code through marked. This vulnerability is fixed in version 2.0.0.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-21306",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "markedjs",
          "product": "marked",
          "versions": [
            {
              "status": "affected",
              "version": ">= 1.1.1, < 2.0.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-02-08T22:15:12.450",
  "references": [
    {
      "url": "https://github.com/markedjs/marked/commit/7293251c438e3ee968970f7609f1a27f9007bccd",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/markedjs/marked/issues/1927",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/markedjs/marked/pull/1864",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/markedjs/marked/security/advisories/GHSA-4r62-v4vq-hr96",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://www.npmjs.com/package/marked",
      "tags": [
        "Product",
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/markedjs/marked/commit/7293251c438e3ee968970f7609f1a27f9007bccd",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/markedjs/marked/issues/1927",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/markedjs/marked/pull/1864",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/markedjs/marked/security/advisories/GHSA-4r62-v4vq-hr96",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.npmjs.com/package/marked",
      "tags": [
        "Product",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Marked is an open-source markdown parser and compiler (npm package \"marked\"). In marked from version 1.1.1 and before version 2.0.0, there is a Regular expression Denial of Service vulnerability. This vulnerability can affect anyone who runs user generated code through marked. This vulnerability is fixed in version 2.0.0."
    },
    {
      "lang": "es",
      "value": "Marked es un analizador y compilador de rebajas de código abierto (paquete npm \"marked\").&#xa0;En marked desde la versión 1.1.1 y anteriores a versión 2.0.0, se presenta una vulnerabilidad de Denegación de Servicio de expresión Regular.&#xa0;Esta vulnerabilidad puede afectar a cualquiera que ejecute código generado por el usuario mediante marked.&#xa0;Esta vulnerabilidad se corrigió en la versión 2.0.0"
    }
  ],
  "lastModified": "2026-06-17T03:35:15.567",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:marked_project:marked:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A9E51743-C978-477B-8B63-EEFC0C7EA788",
              "versionEndExcluding": "2.0.0",
              "versionStartIncluding": "1.1.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}