The vendor explicitly identifies these products as affected by this CVE.
- rh-podman-desktop.git as a component of Red Hat Build of Podman Desktop
- thrift as a component of Red Hat Ceph Storage 9
- thrift.src as a component of Red Hat Ceph Storage 9
- rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend as a component of Red Hat Developer Hub
- rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend as a component of Red Hat Developer Hub
- rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend-module-loki as a component of Red Hat Developer Hub
- rhdh/red-hat-developer-hub-backstage-plugin-scaffolder-backend-module-orchestrator as a component of Red Hat Developer Hub
- rhdh/rhdh-hub-rhel9 as a component of Red Hat Developer Hub
- rhoai/odh-feature-server-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- devspaces/code-rhel9 as a component of Red Hat OpenShift Dev Spaces
- devspaces/openvsx-rhel9 as a component of Red Hat OpenShift Dev Spaces
- Summary
- A flaw was found in markdown-it, a Markdown parser. A remote attacker could exploit this vulnerability to cause a Denial of Service (DoS) when the `typographer` option is enabled. This occurs due to inefficient processing of smartquotes, leading to excessive CPU consumption when parsing specially crafted, quote-heavy markdown input. This can degrade or disrupt service availability for affected applications.
- Remediation
- Fix deferred
