CVE-2020-14001
published 2020-07-17CVE-2020-14001: The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.56%
90.5th percentile
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ruby-kramdown | < ruby-kramdown 2.3.0-3 (bookworm) | ruby-kramdown 2.3.0-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gitlab | gitlab | — | — |
| kramdown_project | kramdown | < 2.3.0 | 2.3.0 |
| kramdown_project | kramdown | >= 0 < 2.3.0 | 2.3.0 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
kramdown vulnerability
vendor_ubuntu·2020-10-26
CVE-2020-14001 kramdown vulnerability
Title: kramdown vulnerability
Summary: kramdown could be made to crash, run programs, or leak sensitive information if
it opened a specially crafted file.
It was discovered that kramdown insecurely handled certain crafted input. An
attacker could use this vulnerability to read restricted files or execute
arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
kramdown vulnerability
vendor_ubuntu·2020-09-30
CVE-2020-14001 kramdown vulnerability
Title: kramdown vulnerability
Summary: kramdown could be made to crash, run programs, or leak sensitive information if
it opened a specially crafted file.
It was discovered that kramdown insecurely handled certain crafted input.
An attacker could use this vulnerability to read restricted files or
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
GitLab
CVE-2020-14001: The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such a
vendor_gitlab·2020-07-17·CVSS 9.8
CVE-2020-14001 [CRITICAL] CWE-862 CVE-2020-14001: The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such a
CVE-2020-14001: The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum.
Red Hat
rubygem-kramdown: processing template options inside documents allows unintended read access or embedded Ruby code execution
vendor_redhat·2020-06-27·CVSS 9.8
CVE-2020-14001 [CRITICAL] CWE-20 rubygem-kramdown: processing template options inside documents allows unintended read access or embedded Ruby code execution
rubygem-kramdown: processing template options inside documents allows unintended read access or embedded Ruby code execution
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum.
A flaw was found in rubygem-kramdown in versions prior to 2.3.0. The template option allows unintended read access or embedded Ruby code execution which is enabled in Kramdown by default. The highest threat from this vulnerability is to data confidentiality and integrity.
Statement: Rubygem-kramdown is not s
Debian
CVE-2020-14001: ruby-kramdown - The kramdown gem before 2.3.0 for Ruby processes the template option inside Kram...
vendor_debian·2020·CVSS 9.8
CVE-2020-14001 [CRITICAL] CVE-2020-14001: ruby-kramdown - The kramdown gem before 2.3.0 for Ruby processes the template option inside Kram...
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum.
Scope: local
bookworm: resolved (fixed in 2.3.0-3)
bullseye: resolved (fixed in 2.3.0-3)
forky: resolved (fixed in 2.3.0-3)
sid: resolved (fixed in 2.3.0-3)
trixie: resolved (fixed in 2.3.0-3)
OSV
Unintended read access in kramdown gem
osv·2020-08-07
CVE-2020-14001 [CRITICAL] Unintended read access in kramdown gem
Unintended read access in kramdown gem
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum.
GHSA
Unintended read access in kramdown gem
ghsa·2020-08-07
CVE-2020-14001 [CRITICAL] CWE-862 Unintended read access in kramdown gem
Unintended read access in kramdown gem
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum.
OSV
CVE-2020-14001: The kramdown gem before 2
osv·2020-07-17·CVSS 9.8
CVE-2020-14001 [CRITICAL] CVE-2020-14001: The kramdown gem before 2
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-14001 rubygem-kramdown: processing template options inside documents allows unintended read access or embedded Ruby code execution
bugzilla·2020-07-17·CVSS 9.8
CVE-2020-14001 [CRITICAL] CVE-2020-14001 rubygem-kramdown: processing template options inside documents allows unintended read access or embedded Ruby code execution
CVE-2020-14001 rubygem-kramdown: processing template options inside documents allows unintended read access or embedded Ruby code execution
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum.
Reference and upstream commit:
https://github.com/gettalong/kramdown/commit/1b8fd33c3120bfc6e5164b449e2c2fc9c9306fde
Discussion:
Created rubygem-kramdown tracking bugs for this issue:
Affects: epel-7 [bug 1858415]
Affects: fedora-all [bug 1858414]
---
Upstream advisory: https://kramdown.ge
Bugzilla
CVE-2020-14001 rubygem-kramdown: processing template options inside documents allows unintended read access or embedded Ruby code execution [epel-7]
bugzilla·2020-07-17·CVSS 9.8
CVE-2020-14001 [CRITICAL] CVE-2020-14001 rubygem-kramdown: processing template options inside documents allows unintended read access or embedded Ruby code execution [epel-7]
CVE-2020-14001 rubygem-kramdown: processing template options inside documents allows unintended read access or embedded Ruby code execution [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg co
Bugzilla
CVE-2020-14001 rubygem-kramdown: processing template options inside documents allows unintended read access or embedded Ruby code execution [fedora-all]
bugzilla·2020-07-17·CVSS 9.8
CVE-2020-14001 [CRITICAL] CVE-2020-14001 rubygem-kramdown: processing template options inside documents allows unintended read access or embedded Ruby code execution [fedora-all]
CVE-2020-14001 rubygem-kramdown: processing template options inside documents allows unintended read access or embedded Ruby code execution [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
f
https://github.com/gettalong/kramdownhttps://github.com/gettalong/kramdown/commit/1b8fd33c3120bfc6e5164b449e2c2fc9c9306fdehttps://github.com/gettalong/kramdown/compare/REL_2_2_1...REL_2_3_0https://kramdown.gettalong.orghttps://kramdown.gettalong.org/news.htmlhttps://lists.apache.org/thread.html/r96df7899fbb456fe2705882f710a0c8e8614b573fbffd8d12e3f54d2%40%3Cnotifications.fluo.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/08/msg00014.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ENMMGKHRQIZ3QKGOMBBBGB6B4LB5I7NQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KBLTGBYU7NKOUOHDKVCU4GFZMGA6BP4L/https://rubygems.org/gems/kramdownhttps://security.netapp.com/advisory/ntap-20200731-0004/https://usn.ubuntu.com/4562-1/https://www.debian.org/security/2020/dsa-4743https://github.com/gettalong/kramdownhttps://github.com/gettalong/kramdown/commit/1b8fd33c3120bfc6e5164b449e2c2fc9c9306fdehttps://github.com/gettalong/kramdown/compare/REL_2_2_1...REL_2_3_0https://kramdown.gettalong.orghttps://kramdown.gettalong.org/news.htmlhttps://lists.apache.org/thread.html/r96df7899fbb456fe2705882f710a0c8e8614b573fbffd8d12e3f54d2%40%3Cnotifications.fluo.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/08/msg00014.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ENMMGKHRQIZ3QKGOMBBBGB6B4LB5I7NQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KBLTGBYU7NKOUOHDKVCU4GFZMGA6BP4L/https://rubygems.org/gems/kramdownhttps://security.netapp.com/advisory/ntap-20200731-0004/https://usn.ubuntu.com/4562-1/https://www.debian.org/security/2020/dsa-4743
2020-07-17
Published