Improper Neutralization of Special Elements in Output Used by a Downstream Component in kramdown - CVE-2020-14001
Published: July 27, 2020
Vulnerability identifier: #VU31897
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14001
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to improper validation of input. A remote attacker can gain read access (such as template="/etc/passwd") or embedded Ruby code execution (such as a string that begins with template="string://<%= `).
Affected software
kramdown
ruby-kramdown (Debian package)
icinga2 (Alpine package)
rubygem-kramdown
ruby2.5-rubygem-kramdown
ruby2.5-rubygem-kramdown-doc
ruby2.5-rubygem-kramdown-testsuite
kramdown (Ubuntu package)
ruby-kramdown (Ubuntu package)
rubygem-kramdown-help
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Storage
Fedora
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise High Availability
SUSE Linux Enterprise Server
openSUSE Leap
openEuler
Ubuntu
ruby-kramdown (Debian package)
icinga2 (Alpine package)
rubygem-kramdown
ruby2.5-rubygem-kramdown
ruby2.5-rubygem-kramdown-doc
ruby2.5-rubygem-kramdown-testsuite
kramdown (Ubuntu package)
ruby-kramdown (Ubuntu package)
rubygem-kramdown-help
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Storage
Fedora
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise High Availability
SUSE Linux Enterprise Server
openSUSE Leap
openEuler
Ubuntu
How to mitigate CVE-2020-14001
Install update from vendor's website.
kramdown - update to 2.3.0
ruby-kramdown (Debian package) - update to 1.17.0-1+deb10u1
icinga2 (Alpine package) - update to 2.11.3-r1
rubygem-kramdown - addressed in versions 1.9.0-2.el7, 1.17.0-6.fc31, 2.1.0-3.fc32, 2.2.1-4.fc32
ruby2.5-rubygem-kramdown - update to 1.15.0-150000.3.3.1
ruby2.5-rubygem-kramdown-doc - update to 1.15.0-150000.3.3.1
ruby2.5-rubygem-kramdown-testsuite - update to 1.15.0-150000.3.3.1
kramdown (Ubuntu package) - addressed in versions 1.17.0-4ubuntu0.1, 1.17.0-4ubuntu0.20.10.1
ruby-kramdown (Ubuntu package) - addressed in versions 1.17.0-4ubuntu0.1, 1.17.0-4ubuntu0.20.10.1
rubygem-kramdown - update to 2.1.0-3
rubygem-kramdown-help - update to 2.1.0-3
ruby-kramdown (Debian package) - update to 1.17.0-1+deb10u1
icinga2 (Alpine package) - update to 2.11.3-r1
rubygem-kramdown - addressed in versions 1.9.0-2.el7, 1.17.0-6.fc31, 2.1.0-3.fc32, 2.2.1-4.fc32
ruby2.5-rubygem-kramdown - update to 1.15.0-150000.3.3.1
ruby2.5-rubygem-kramdown-doc - update to 1.15.0-150000.3.3.1
ruby2.5-rubygem-kramdown-testsuite - update to 1.15.0-150000.3.3.1
kramdown (Ubuntu package) - addressed in versions 1.17.0-4ubuntu0.1, 1.17.0-4ubuntu0.20.10.1
ruby-kramdown (Ubuntu package) - addressed in versions 1.17.0-4ubuntu0.1, 1.17.0-4ubuntu0.20.10.1
rubygem-kramdown - update to 2.1.0-3
rubygem-kramdown-help - update to 2.1.0-3
External References
Related Security Bulletins
- Remote code execution in kramdown gem for Ruby
- Debian update for ruby-kramdown
- Improper Neutralization of Special Elements in Output Used by a Downstream Component in icinga2 (Alpine package)
- SUSE update for rubygem-kramdown
- openEuler update for rubygem-kramdown
- Ubuntu update for ruby-kramdown
- Ubuntu update for ruby-kramdown
- Fedora 32 update for rubygem-kramdown
- Fedora 31 update for rubygem-kramdown
- Fedora 32 update for rubygem-kramdown
- Fedora EPEL 7 update for rubygem-kramdown