asciidoctor-include-ext
This is a reimplementation of the Asciidoctor's built-in (pre)processor for the include::[] directive in extensible and more clean way. It provides the same features, but you can easily adjust it or extend for your needs. For example, you can change how it loads included files or add another ways how to select portions of the document to include.
Activity
- Latest release
- 4y ago
- Total releases
- 6
- Cadence
- ~5 months
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Dec 12, 2017
| Version | Released | |
|---|---|---|
0.4.0
minor
| ||
0.3.1
patch
1 CVE
CVE-2022-24803
GHSA-v222-6mr4-qj29
Mar 31, 2022
Command Injection vulnerability in asciidoctor-include-ext
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactApplications using Asciidoctor (Ruby) with asciidoctor-include-ext (prior to version 0.4.0), which render user-supplied input in AsciiDoc markup, may allow an attacker to execute arbitrary system commands on the host operating system. ~~This attack is possible even when PatchesThe vulnerability has been fixed in commit c7ea001 (and further improved in cbaccf3), which is included in version 0.4.0. Workarounds
References
CreditsThis vulnerability was discovered by Joern Schneeweisz from the GitLab Security Research Team. For more informationSee commit message c7ea001. If you have any questions or comments about this advisory open an issue in jirutka/asciidoctor-include-ext. Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
Fixed in
0.4.0
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.3.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
0.3.0
minor
1 CVE
CVE-2022-24803
GHSA-v222-6mr4-qj29
Mar 31, 2022
Command Injection vulnerability in asciidoctor-include-ext
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactApplications using Asciidoctor (Ruby) with asciidoctor-include-ext (prior to version 0.4.0), which render user-supplied input in AsciiDoc markup, may allow an attacker to execute arbitrary system commands on the host operating system. ~~This attack is possible even when PatchesThe vulnerability has been fixed in commit c7ea001 (and further improved in cbaccf3), which is included in version 0.4.0. Workarounds
References
CreditsThis vulnerability was discovered by Joern Schneeweisz from the GitLab Security Research Team. For more informationSee commit message c7ea001. If you have any questions or comments about this advisory open an issue in jirutka/asciidoctor-include-ext. Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
Fixed in
0.4.0
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.3.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
0.2.0
minor
1 CVE
CVE-2022-24803
GHSA-v222-6mr4-qj29
Mar 31, 2022
Command Injection vulnerability in asciidoctor-include-ext
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactApplications using Asciidoctor (Ruby) with asciidoctor-include-ext (prior to version 0.4.0), which render user-supplied input in AsciiDoc markup, may allow an attacker to execute arbitrary system commands on the host operating system. ~~This attack is possible even when PatchesThe vulnerability has been fixed in commit c7ea001 (and further improved in cbaccf3), which is included in version 0.4.0. Workarounds
References
CreditsThis vulnerability was discovered by Joern Schneeweisz from the GitLab Security Research Team. For more informationSee commit message c7ea001. If you have any questions or comments about this advisory open an issue in jirutka/asciidoctor-include-ext. Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
Fixed in
0.4.0
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.2.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
0.1.1
patch
1 CVE
CVE-2022-24803
GHSA-v222-6mr4-qj29
Mar 31, 2022
Command Injection vulnerability in asciidoctor-include-ext
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactApplications using Asciidoctor (Ruby) with asciidoctor-include-ext (prior to version 0.4.0), which render user-supplied input in AsciiDoc markup, may allow an attacker to execute arbitrary system commands on the host operating system. ~~This attack is possible even when PatchesThe vulnerability has been fixed in commit c7ea001 (and further improved in cbaccf3), which is included in version 0.4.0. Workarounds
References
CreditsThis vulnerability was discovered by Joern Schneeweisz from the GitLab Security Research Team. For more informationSee commit message c7ea001. If you have any questions or comments about this advisory open an issue in jirutka/asciidoctor-include-ext. Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
Fixed in
0.4.0
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.1.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
0.1.0
initial
1 CVE
CVE-2022-24803
GHSA-v222-6mr4-qj29
Mar 31, 2022
Command Injection vulnerability in asciidoctor-include-ext
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactApplications using Asciidoctor (Ruby) with asciidoctor-include-ext (prior to version 0.4.0), which render user-supplied input in AsciiDoc markup, may allow an attacker to execute arbitrary system commands on the host operating system. ~~This attack is possible even when PatchesThe vulnerability has been fixed in commit c7ea001 (and further improved in cbaccf3), which is included in version 0.4.0. Workarounds
References
CreditsThis vulnerability was discovered by Joern Schneeweisz from the GitLab Security Research Team. For more informationSee commit message c7ea001. If you have any questions or comments about this advisory open an issue in jirutka/asciidoctor-include-ext. Affected versions
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
Fixed in
0.4.0
References
Updated Nov 08, 2023 · Source: OSV.dev |