CVE-2021-28834
19.03.2021, 07:15
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.Enginsight
| Vendor | Product | Version |
|---|---|---|
| kramdown_project | kramdown | 𝑥 < 2.3.1 |
| debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| kramdown |
| ||||||||||||||||||||
| ruby-kramdown |
| ||||||||||||||||||||
| ruby-kramdown-rfc2629 |
|
References