CVE-2021-28834: Critical severity kramdown vulnerability
Published Mar 19, 2021
·Updated
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.
Affected Software
10 affected componentsFixes available
debian/ruby-kramdown<=2.3.0-4, <=1.17.0-1+deb10u1, <=1.17.0-1
2.3.0-51.17.0-1+deb10u2
redhat/rubygem-kramdown<2.3.1
2.3.1
debian/ruby-kramdown
1.17.0-1+deb10u22.3.0-52.4.0-2
ubuntu/ruby-kramdown<1.17.0-4ubuntu0.2
1.17.0-4ubuntu0.2
ubuntu/ruby-kramdown<2.3.1
2.3.1
Kramdown Project Kramdown Ruby<2.3.1
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Debian Debian Linux=10.0
Remediation
Event History
Mar 19, 2021
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·06:51 AM
Data Sourced
via MITRE·06:51 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:56 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-28834?
The severity of CVE-2021-28834 is medium.
2
Which software is affected by CVE-2021-28834?
The software affected by CVE-2021-28834 is ruby-kramdown version 1.17.0-1+deb10u2, 2.3.0-5, 2.4.0-2, and rubygem-kramdown version up to 2.3.1.
3
How can arbitrary classes be instantiated in Kramdown before version 2.3.1?
Kramdown before version 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, allowing arbitrary classes to be instantiated.
4
What is the fix for CVE-2021-28834?
To fix CVE-2021-28834, update to kramdown version 2.3.1 or higher.
5
Where can I find more information about CVE-2021-28834?
More information about CVE-2021-28834 can be found on the [CVE website](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28834) and on the [GitHub page](https://github.com/gettalong/kramdown/pull/708).