CVE-2021-28834
19.03.2021, 07:15
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.Enginsight
Vendor | Product | Version |
---|---|---|
kramdown_project | kramdown | 𝑥 < 2.3.1 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
kramdown |
| ||||||||||||||||||||
ruby-kramdown |
| ||||||||||||||||||||
ruby-kramdown-rfc2629 |
|
References