Total vulnerabilities in the database
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.
Software | From | Fixed in |
---|---|---|
kramdown_project / kramdown | - | 2.3.1 |
fedoraproject / fedora | 32 | 32.x |
fedoraproject / fedora | 33 | 33.x |
fedoraproject / fedora | 34 | 34.x |
debian / debian_linux | 10.0 | 10.0.x |
![]() |
1.16.0 | 2.3.1 |