OESA-2021-1175

    Dashboard / Vulnerabilities / OESA-2021-1175

    OESA-2021-1175

    Published: 6 May 2021Last Modified: 18 Aug 2026
    Upstream:

    Summary: rubygem-redcarpet security update

    Details: A fast, safe and extensible Markdown to (X)HTML parser. Security Fix(es): Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the `:escape_html` option was being used. This is fixed in version 3.5.1 by the referenced commit.(CVE-2020-26298)

    Affected packages

    Package

    Name: rubygem-redcarpet

    Purl: pkg:rpm/openEuler/rubygem-redcarpet&distro=openEuler-20.03-LTS-SP1

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.5.1-1.oe1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    OESA-2021-1175 | CVE-DB