Vulnerabilities > CVE-2021-28834

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
kramdown-project
fedoraproject
debian
critical

Summary

Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.

Vulnerable Configurations

Part Description Count
Application
Kramdown_Project
62
OS
Fedoraproject
3
OS
Debian
1