Moderate severityNVD Advisory· Published Jun 21, 2021· Updated Aug 3, 2024
CVE-2021-28833
CVE-2021-28833
Description
Increments Qiita::Markdown before 0.34.0 allows XSS via a crafted gist link, a different vulnerability than CVE-2021-28796.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
qiita-markdownRubyGems | < 0.34.0 | 0.34.0 |
Affected products
2- Qiita/Qiita::Markdowndescription
Patches
Vulnerability mechanics
Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
6- github.com/advisories/GHSA-9p29-94hp-8rvcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-28833ghsaADVISORY
- github.com/increments/qiita-markdown/commit/b5d4e60bf537ceb177e70bf91653d29575e1aa21ghsaWEB
- github.com/increments/qiita-markdown/compare/v0.33.0...v0.34.0ghsaWEB
- github.com/increments/qiita-markdown/releasesghsax_refsource_MISCWEB
- vuln.ryotak.me/advisories/50ghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.