漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS
Vulnerability Description
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when rendering gantt charts, if they use the excludes attribute to exclude all dates. mermaid.parse is unaffected, unless you then call the ganttDb.getTasks() (which is called when rendering a diagram). This vulnerability is fixed in 10.9.6 and 11.15.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
Vulnerability Type
不可达退出条件的循环(无限循环)
Vulnerability Title
Mermaid 安全漏洞
Vulnerability Description
Mermaid是mermaid-js开源的一个应用软件。使用文本和代码创建图表和可视化。 Mermaid 10.9.6之前版本和11.15.0之前版本存在安全漏洞,该漏洞源于在渲染甘特图时,如果使用excludes属性排除所有日期,则会导致拒绝服务攻击。mermaid.parse不受影响,除非随后调用ganttDb.getTasks。
CVSS Information
N/A
Vulnerability Type
N/A