Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mqm2-cgpr-p4m6

Опубликовано: 07 авг. 2020
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Unintended read access in kramdown gem

The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum.

Пакеты

Наименование

kramdown

rubygems
Затронутые версииВерсия исправления

< 2.3.0

2.3.0

EPSS

Процентиль: 93%
0.09348
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 5 лет назад

The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum.

CVSS3: 9.1
redhat
больше 5 лет назад

The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum.

CVSS3: 9.8
nvd
больше 5 лет назад

The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum.

CVSS3: 9.8
debian
больше 5 лет назад

The kramdown gem before 2.3.0 for Ruby processes the template option i ...

suse-cvrf
больше 3 лет назад

Security update for rubygem-kramdown

EPSS

Процентиль: 93%
0.09348
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-862