CVE-2020-14001 is a critical vulnerability in the kramdown Ruby gem, affecting products like Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. It allows unauthenticated attackers to achieve arbitrary file read or embedded Ruby code execution due to improper processing of the 'template' option within Kramdown documents. With a CVSS score of 9.8, this vulnerability poses a severe risk of complete compromise of confidentiality, integrity, and availability. While there are no public exploits or KEV entries, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.0CPE matchmatch criteria | cpe:2.3:a:kramdown_project:kramdown:*:*:*:*:*:ruby:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.