Redcarpet Project Redcarpet 2.0.1 for Ruby

CPE Details

Redcarpet Project Redcarpet 2.0.1 for Ruby
2.0.1
2021-01-13
14h32 +00:00
2021-01-13
14h32 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:redcarpet_project:redcarpet:2.0.1:*:*:*:*:ruby:*:*

Informations

Vendor

redcarpet_project

Product

redcarpet

Version

2.0.1

Target Software

ruby

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2020-26298 2021-01-11 00h00 +00:00 Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the `:escape_html` option was being used. This is fixed in version 3.5.1 by the referenced commit.
6.8
Medium
CVE-2015-5147 2015-07-14 14h00 +00:00 Stack-based buffer overflow in the header_anchor function in the HTML renderer in Redcarpet before 3.3.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
7.5