CVE-2018-17567
28.09.2018, 00:29
Jekyll through 3.6.2, 3.7.x through 3.7.3, and 3.8.x through 3.8.3 allows attackers to access arbitrary files by specifying a symlink in the "include" key in the "_config.yml" file.
Vendor | Product | Version |
---|---|---|
jekyllrb | jekyll | 𝑥 ≤ 3.6.2 |
jekyllrb | jekyll | 3.7.0 ≤ 𝑥 ≤ 3.7.3 |
jekyllrb | jekyll | 3.8.0 ≤ 𝑥 ≤ 3.8.3 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References