CVE-2021-28834
published 2021-03-19CVE-2021-28834: Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.
PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.80%
84.9th percentile
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | ruby-kramdown | < ruby-kramdown 2.3.0-5 (bookworm) | ruby-kramdown 2.3.0-5 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| kramdown_project | kramdown | < 2.3.1 | 2.3.1 |
| kramdown_project | kramdown | >= 1.16.0 < 2.3.1 | 2.3.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
kramdown vulnerability
vendor_ubuntu·2023-10-10
CVE-2021-28834 kramdown vulnerability
Title: kramdown vulnerability
Summary: kramdown could be made to execute arbitrary code if it received specially
crafted input.
It was discovered that kramdown did not restrict Rouge formatters to the
correct namespace. An attacker could use this issue to cause kramdown to
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
rubygem-kramdown: allows arbitrary classes to be instantiated
vendor_redhat·2021-03-14·CVSS 9.8
CVE-2021-28834 [CRITICAL] CWE-470 rubygem-kramdown: allows arbitrary classes to be instantiated
rubygem-kramdown: allows arbitrary classes to be instantiated
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.
A flaw was found in rubygem-kramdown. Rouge is a syntax highlighter used by kramdown. Restriction of the Rouge formatters to the Rouge::Formatters namespace does not occur when Ruby's const_get() method is called. This can lead to arbitrary classes being instantiated in situations where the application using kramdown, for example, accepts user input to select a Rogue syntax highlighter formatter. The highest threat from this vulnerability when exploited in a vulnerable configuration is to data confidentiality, integrity, and availability.
Statement: Red Hat supported products are not aff
Debian
CVE-2021-28834: ruby-kramdown - Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatter...
vendor_debian·2021·CVSS 9.8
CVE-2021-28834 [CRITICAL] CVE-2021-28834: ruby-kramdown - Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatter...
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.
Scope: local
bookworm: resolved (fixed in 2.3.0-5)
bullseye: resolved (fixed in 2.3.0-5)
forky: resolved (fixed in 2.3.0-5)
sid: resolved (fixed in 2.3.0-5)
trixie: resolved (fixed in 2.3.0-5)
GHSA
Remote code execution in Kramdown
ghsa·2021-03-29
CVE-2021-28834 [HIGH] CWE-94 Remote code execution in Kramdown
Remote code execution in Kramdown
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.
OSV
Remote code execution in Kramdown
osv·2021-03-29
CVE-2021-28834 [HIGH] Remote code execution in Kramdown
Remote code execution in Kramdown
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.
OSV
CVE-2021-28834: Kramdown before 2
osv·2021-03-19·CVSS 9.8
CVE-2021-28834 [CRITICAL] CVE-2021-28834: Kramdown before 2
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/gettalong/kramdown/compare/REL_2_3_0...REL_2_3_1https://github.com/gettalong/kramdown/pull/708https://gitlab.com/gitlab-org/gitlab/-/commit/179329b5c3c118924fb242dc449d06b4ed6ccb66https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJCJVYHPY6LNUFM6LYZIAUIYOMVT5QGV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S3BBLUIDCUUR3NEE4NJLOCCAV3ALQ3O6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SYOLQKFL6IJCQLBXV34Z4TI4O54GESPR/https://www.debian.org/security/2021/dsa-4890https://github.com/gettalong/kramdown/compare/REL_2_3_0...REL_2_3_1https://github.com/gettalong/kramdown/pull/708https://gitlab.com/gitlab-org/gitlab/-/commit/179329b5c3c118924fb242dc449d06b4ed6ccb66https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJCJVYHPY6LNUFM6LYZIAUIYOMVT5QGV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S3BBLUIDCUUR3NEE4NJLOCCAV3ALQ3O6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SYOLQKFL6IJCQLBXV34Z4TI4O54GESPR/https://www.debian.org/security/2021/dsa-4890
2021-03-19
Published