Lucene search

K
osvGoogleOSV:CVE-2021-28834
HistoryMar 19, 2021 - 7:15 a.m.

CVE-2021-28834

2021-03-1907:15:13
Google
osv.dev
5
kramdown
version 2.3.1
rouge formatters
arbitrary classes
instantiation
security vulnerability

AI Score

6.7

Confidence

Low

EPSS

0.02

Percentile

88.9%

Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.