Back to Database
Status published
Critical
CVE-2021-28834
Kramdown before 2.3.1 does not restrict Rouge formatters to the...
Vulnerability Description
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-28834
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/gettalong/kramdown/pull/708
- https://gitlab.com/gitlab-org/gitlab/-/commit/179329b5c3c118924fb242dc449d06b4ed6ccb66
- https://github.com/gettalong/kramdown/compare/REL_2_3_0...REL_2_3_1
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S3BBLUIDCUUR3NEE4NJLOCCAV3ALQ3O6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SYOLQKFL6IJCQLBXV34Z4TI4O54GESPR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJCJVYHPY6LNUFM6LYZIAUIYOMVT5QGV/
- https://www.debian.org/security/2021/dsa-4890
More from kramdown project
View All →Affected Vendor
kramdown project
View all reports →Affected Software
kramdown, fedora, debian linux
Vulnerable Versions:
0, 32, 33, 34, 10.0
Timeline
Official Publish:
March 19th, 2021
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.