CVE-2020-26298

redcarpet
on gem
vmg/redcarpet
on github

Published

Severity

CVSS v3:
5.4 MEDIUM
CVSS v2:
3.5 LOW

Description

Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the `:escape_html` option was being used. This is fixed in version 3.5.1 by the referenced commit.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:redcarpet_project:redcarpet:*:*:*:*:*:ruby:*:*n/a3.5.1*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*n/an/a9.0
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*n/an/a10.0

External Links