PT-2021-5816 · Kramdown+4 · Kramdown+4

Stan Hu

·

Published

2021-03-14

·

Updated

2026-03-13

·

CVE-2021-28834

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kramdown versions prior to 2.3.1
Description The issue is related to the lack of restriction of Rouge formatters to the Rouge::Formatters namespace, allowing arbitrary classes to be instantiated. This could potentially enable a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations For versions prior to 2.3.1, update to version 2.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Rouge formatters to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1602
BDU:2022-00305
CVE-2021-28834
DSA-4890-1
GHSA-52P9-V744-MWJJ
OESA-2021-1159
OPENSUSE-SU-2024:11336-1
OPENSUSE-SU-2024:12038-1
OPENSUSE-SU-2024:13161-1
OPENSUSE-SU-2024:14170-1
OPENSUSE-SU-2025:15119-1
OPENSUSE-SU-2026:10352-1
USN-6424-1

Affected Products

Alt Linux
Astra Linux
Kramdown
Linuxmint
Ubuntu