VYPR
Vendor

Kramdown Project

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2021-28834CriMar 19, 2021
    risk 0.57cvss 9.8epss 0.03

    Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.

  • CVE-2020-14001CriJul 17, 2020
    risk 0.57cvss 9.8epss 0.05

    The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%=…