OESA-2021-1280

    Dashboard / Vulnerabilities / OESA-2021-1280

    OESA-2021-1280

    Published: 27 Jul 2021Last Modified: 18 Aug 2026
    Upstream:

    Summary: rubygem-kramdown security update

    Details: kramdown is yet-another-markdown-parser but fast, pure Ruby, using a strict syntax definition and supporting several common extensions. Security Fix(es): The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum.(CVE-2020-14001)

    Affected packages

    Package

    Name: rubygem-kramdown

    Purl: pkg:rpm/openEuler/rubygem-kramdown&distro=openEuler-20.03-LTS-SP1

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.1.0-3.oe1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    OESA-2021-1280 | CVE-DB