Improper Neutralization of Special Elements in Output Used by a Downstream Component in kramdown - CVE-2020-14001

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in kramdown - CVE-2020-14001

Published: July 27, 2020


Vulnerability identifier: #VU31897
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14001
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the system.

The vulnerability exists due to improper validation of input. A remote attacker can gain read access (such as template="/etc/passwd") or embedded Ruby code execution (such as a string that begins with template="string://<%= `).


Affected software

kramdown
ruby-kramdown (Debian package)
icinga2 (Alpine package)
rubygem-kramdown
ruby2.5-rubygem-kramdown
ruby2.5-rubygem-kramdown-doc
ruby2.5-rubygem-kramdown-testsuite
kramdown (Ubuntu package)
ruby-kramdown (Ubuntu package)
rubygem-kramdown-help
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Storage
Fedora
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise High Availability
SUSE Linux Enterprise Server
openSUSE Leap
openEuler
Ubuntu

How to mitigate CVE-2020-14001

Install update from vendor's website.

kramdown - update to 2.3.0
ruby-kramdown (Debian package) - update to 1.17.0-1+deb10u1
icinga2 (Alpine package) - update to 2.11.3-r1
rubygem-kramdown - addressed in versions 1.9.0-2.el7, 1.17.0-6.fc31, 2.1.0-3.fc32, 2.2.1-4.fc32
ruby2.5-rubygem-kramdown - update to 1.15.0-150000.3.3.1
ruby2.5-rubygem-kramdown-doc - update to 1.15.0-150000.3.3.1
ruby2.5-rubygem-kramdown-testsuite - update to 1.15.0-150000.3.3.1
kramdown (Ubuntu package) - addressed in versions 1.17.0-4ubuntu0.1, 1.17.0-4ubuntu0.20.10.1
ruby-kramdown (Ubuntu package) - addressed in versions 1.17.0-4ubuntu0.1, 1.17.0-4ubuntu0.20.10.1
rubygem-kramdown - update to 2.1.0-3
rubygem-kramdown-help - update to 2.1.0-3

External References

Related Security Bulletins