VDB

CVE-2020-14001

CVE-2020-14001 PUBLISHED

The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum.

EPSS 7.51% · 91.9th percentile

Risk Scores

EPSS Score
7.51%
91.9th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSruby-kramdown0, 1.14.0-1, 1.15.0-1
Ubuntu:20.04:LTSruby-kramdown0, 1.17.0-4, 1.17.0-2
Ubuntu:16.04:LTSruby-kramdown1.8.0-1, 1.10.0-1, 0

Timeline

  • Jul 17, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 22, 2021 EPSS Score
  • Jul 21, 2021 CVE Updated
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 27, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 5, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›