CVE-2021-28834

NameCVE-2021-28834
DescriptionKramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-4890-1
Debian Bugs985569

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ruby-kramdown (PTS)buster, buster (security)1.17.0-1+deb10u2fixed
bullseye2.3.0-5fixed
trixie, bookworm, sid2.4.0-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ruby-kramdownsourcestretch(not affected)
ruby-kramdownsourcebuster1.17.0-1+deb10u2DSA-4890-1
ruby-kramdownsource(unstable)2.3.0-5985569

Notes

[stretch] - ruby-kramdown <not-affected> (Vulnerable code introduced later)
https://github.com/gettalong/kramdown/pull/708
Fixed by: https://github.com/gettalong/kramdown/commit/d6a1cbcb2caa2f8a70927f176070d126b2422760
Introduced by https://github.com/gettalong/kramdown/commit/ff0218aefcf00cd5a389e17e075d36cd46d011e2 (v1.16)

Search for package or bug name: Reporting problems