Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Stan Hu

#24084of 53,630
9.8Total CVSS
Vulnerabilities · 1
PT-2021-5816
9.8
2021-03-14
Kramdown · Kramdown · CVE-2021-28834
**Name of the Vulnerable Software and Affected Versions** Kramdown versions prior to 2.3.1 **Description** The issue is related to the lack of restriction of Rouge formatters to the Rouge::Formatters namespace, allowing arbitrary classes to be instantiated. This could potentially enable a remote attacker to access confidential data, compromise its integrity, and cause a denial of service. **Recommendations** For versions prior to 2.3.1, update to version 2.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Rouge formatters to minimize the risk of exploitation.