CVE-2024-28243
KaTeX's maxExpand bypassed by `\edef`
6.5
MEDIUM
CVSS 3.1
EPSS 1.4%
描述
KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\edef` that causes a near-infinite loop, despite setting `maxExpand` to avoid such loops. This can be used as an availability attack, where e.g. a client rendering another user's KaTeX input will be unable to use the site due to memory overflow, tying up the main thread, or stack overflow. Upgrade to KaTeX v0.16.10 to remove this vulnerability.
如何修補 CVE-2024-28243
要修補 CVE-2024-28243,請將受影響套件升級到下列已修補版本。
- —未列出修補版本
- —升級至 0.16.10 或更新版本
CVE-2024-28243 正在被利用嗎?
低 — EPSS 為 1.4%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0
- >= 0.12.0, < 0.16.10
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |