kramdown
kramdown is yet-another-markdown-parser but fast, pure Ruby, using a strict syntax definition and supporting several common extensions.
Activity
- Latest release
- 7mo ago
- Total releases
- 66
- Cadence
- ~2 months
- Last 12 months
- 1
Details
- License
- MIT
- First release
- Nov 20, 2009
| Version | Released | |
|---|---|---|
2.5.2
patch
| ||
2.5.1
patch
| ||
2.5.0
minor
| ||
2.4.0
minor
| ||
2.3.2
patch
| ||
2.3.1
patch
| ||
2.3.0
minor
1 CVE
CVE-2021-28834
GHSA-52p9-v744-mwjj
Mar 29, 2021
Remote code execution in Kramdown
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated. Affected versions
1.16.0
1.16.1
1.16.2
1.17.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Feb 17, 2024 · Source: OSV.dev | ||
2.2.1
patch
2 CVEs
CVE-2021-28834
GHSA-52p9-v744-mwjj
Mar 29, 2021
Remote code execution in Kramdown
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated. Affected versions
1.16.0
1.16.1
1.16.2
1.17.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Feb 17, 2024 · Source: OSV.dev
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
2.2.0
minor
2 CVEs
CVE-2021-28834
GHSA-52p9-v744-mwjj
Mar 29, 2021
Remote code execution in Kramdown
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated. Affected versions
1.16.0
1.16.1
1.16.2
1.17.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Feb 17, 2024 · Source: OSV.dev
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
2.1.0
minor
2 CVEs
CVE-2021-28834
GHSA-52p9-v744-mwjj
Mar 29, 2021
Remote code execution in Kramdown
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated. Affected versions
1.16.0
1.16.1
1.16.2
1.17.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Feb 17, 2024 · Source: OSV.dev
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
2.0.0
major
2 CVEs
CVE-2021-28834
GHSA-52p9-v744-mwjj
Mar 29, 2021
Remote code execution in Kramdown
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated. Affected versions
1.16.0
1.16.1
1.16.2
1.17.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Feb 17, 2024 · Source: OSV.dev
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
2.0.0.beta1
pre
2 CVEs
CVE-2021-28834
GHSA-52p9-v744-mwjj
Mar 29, 2021
Remote code execution in Kramdown
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated. Affected versions
1.16.0
1.16.1
1.16.2
1.17.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Feb 17, 2024 · Source: OSV.dev
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
2.0.0.beta2
pre
2 CVEs
CVE-2021-28834
GHSA-52p9-v744-mwjj
Mar 29, 2021
Remote code execution in Kramdown
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated. Affected versions
1.16.0
1.16.1
1.16.2
1.17.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Feb 17, 2024 · Source: OSV.dev
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
1.17.0
minor
2 CVEs
CVE-2021-28834
GHSA-52p9-v744-mwjj
Mar 29, 2021
Remote code execution in Kramdown
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated. Affected versions
1.16.0
1.16.1
1.16.2
1.17.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Feb 17, 2024 · Source: OSV.dev
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev |
1.17.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
1.16.2
patch
2 CVEs
CVE-2021-28834
GHSA-52p9-v744-mwjj
Mar 29, 2021
Remote code execution in Kramdown
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated. Affected versions
1.16.0
1.16.1
1.16.2
1.17.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Feb 17, 2024 · Source: OSV.dev
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev |
1.16.2
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
1.16.1
patch
2 CVEs
CVE-2021-28834
GHSA-52p9-v744-mwjj
Mar 29, 2021
Remote code execution in Kramdown
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated. Affected versions
1.16.0
1.16.1
1.16.2
1.17.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Feb 17, 2024 · Source: OSV.dev
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev |
1.16.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
1.16.0
minor
2 CVEs
CVE-2021-28834
GHSA-52p9-v744-mwjj
Mar 29, 2021
Remote code execution in Kramdown
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated. Affected versions
1.16.0
1.16.1
1.16.2
1.17.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
2.3.0
Fixed in
2.3.1
References
Updated Feb 17, 2024 · Source: OSV.dev
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev |
1.16.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
1.15.0
minor
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev |
1.15.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
1.14.0
minor
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev |
1.14.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
1.13.2
patch
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev |
1.13.2
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.13.1
patch
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev |
1.13.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.13.0
minor
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev |
1.13.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
1.12.0
minor
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev |
1.12.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
1.11.1
patch
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev |
1.11.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.11.0
minor
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev |
1.11.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
1.10.0
minor
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
1.9.0
minor
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
1.8.0
minor
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
1.7.0
minor
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
1.6.0
minor
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
1.5.0
minor
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
1.4.2
patch
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
1.4.1
patch
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
1.4.0
minor
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
1.3.3
patch
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
1.3.2
patch
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
1.3.1
patch
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
1.3.0
minor
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
1.2.0
minor
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
1.1.0
minor
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
1.0.2
patch
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
1.0.1
patch
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
1.0.0
major
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.14.2
patch
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.14.1
patch
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.14.0
minor
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.13.8
patch
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.13.7
patch
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.13.6
patch
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev | ||
0.13.5
patch
1 CVE
CVE-2020-14001
GHSA-mqm2-cgpr-p4m6
Aug 07, 2020
Unintended read access in kramdown gem
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.13.8
+ 47 more Show less
0.14.0
0.14.1
0.14.2
0.2.0
0.3.0
0.4.0
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
1.0.0
1.0.1
1.0.2
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.14.0
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.6.0
1.7.0
1.8.0
1.9.0
2.0.0
2.0.0.beta1
2.0.0.beta2
2.1.0
2.2.0
2.2.1
Fixed in
2.3.0
References
Updated Feb 18, 2024 · Source: OSV.dev |