CVE-2020-26298
published 2021-01-11CVE-2020-26298: Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site…
PriorityP428medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
1.57%
72.9th percentile
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the `:escape_html` option was being used. This is fixed in version 3.5.1 by the referenced commit.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ruby-redcarpet | < ruby-redcarpet 3.5.1-1 (bookworm) | ruby-redcarpet 3.5.1-1 (bookworm) |
| redcarpet_project | redcarpet | < 3.5.1 | 3.5.1 |
| redcarpet_project | redcarpet | >= 0 < 3.5.1 | 3.5.1 |
| vmg | redcarpet | < 3.5.1 | 3.5.1 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv5.4MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rubygem-redcarpet: does not escape HTML when processing quotes which could result in XSS vulnerability
vendor_redhat·2021-01-11·CVSS 6.8
CVE-2020-26298 [MEDIUM] CWE-79 rubygem-redcarpet: does not escape HTML when processing quotes which could result in XSS vulnerability
rubygem-redcarpet: does not escape HTML when processing quotes which could result in XSS vulnerability
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the `:escape_html` option was being used. This is fixed in version 3.5.1 by the referenced commit.
Package: redcarpet (Red Hat 3scale API Management Platform 2) - Affected
Debian
CVE-2020-26298: ruby-redcarpet - Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version...
vendor_debian·2020·CVSS 6.8
CVE-2020-26298 [MEDIUM] CVE-2020-26298: ruby-redcarpet - Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version...
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the `:escape_html` option was being used. This is fixed in version 3.5.1 by the referenced commit.
Scope: local
bookworm: resolved (fixed in 3.5.1-1)
bullseye: resolved (fixed in 3.5.1-1)
forky: resolved (fixed in 3.5.1-1)
sid: resolved (fixed in 3.5.1-1)
trixie: resolved (fixed in 3.5.1-1)
GHSA
Injection/XSS in Redcarpet
ghsa·2021-01-11
CVE-2020-26298 [MEDIUM] CWE-74 Injection/XSS in Redcarpet
Injection/XSS in Redcarpet
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the `:escape_html` option was being used. This is fixed in version 3.5.1 by the referenced commit.
OSV
CVE-2020-26298: Redcarpet is a Ruby library for Markdown processing
osv·2021-01-11·CVSS 5.4
CVE-2020-26298 [MEDIUM] CVE-2020-26298: Redcarpet is a Ruby library for Markdown processing
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the `:escape_html` option was being used. This is fixed in version 3.5.1 by the referenced commit.
OSV
Injection/XSS in Redcarpet
osv·2021-01-11
CVE-2020-26298 [MEDIUM] Injection/XSS in Redcarpet
Injection/XSS in Redcarpet
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the `:escape_html` option was being used. This is fixed in version 3.5.1 by the referenced commit.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/advisories/GHSA-q3wr-qw3g-3p4hhttps://github.com/vmg/redcarpet/blob/master/CHANGELOG.md#version-351-securityhttps://github.com/vmg/redcarpet/commit/a699c82292b17c8e6a62e1914d5eccc252272793https://lists.debian.org/debian-lts-announce/2021/01/msg00014.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFMYDIONVWATY7EB6EARDVXT47AYCRNM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNO4ZZUPGAEUXKQL4G2HRIH7CUZKPCT6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PXNNWHHAPREDM3XJDACYRTK7DBMUONBI/https://rubygems.org/gems/redcarpethttps://www.debian.org/security/2021/dsa-4831https://github.com/advisories/GHSA-q3wr-qw3g-3p4hhttps://github.com/vmg/redcarpet/blob/master/CHANGELOG.md#version-351-securityhttps://github.com/vmg/redcarpet/commit/a699c82292b17c8e6a62e1914d5eccc252272793https://lists.debian.org/debian-lts-announce/2021/01/msg00014.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFMYDIONVWATY7EB6EARDVXT47AYCRNM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNO4ZZUPGAEUXKQL4G2HRIH7CUZKPCT6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PXNNWHHAPREDM3XJDACYRTK7DBMUONBI/https://rubygems.org/gems/redcarpethttps://www.debian.org/security/2021/dsa-4831
2021-01-11
Published