Index: security/vuxml/vuln.xml =================================================================== --- security/vuxml/vuln.xml +++ security/vuxml/vuln.xml @@ -57,6 +57,35 @@ --> + + rubygem-redcarpet -- XSS vulnerability + + + rubygem-redcarpet + 3.2.3 + + + + +

Daniel LeCheminant reports:

+
+

When markdown is being presented as HTML, there seems to be a + strange interaction between _ and @ that lets an attacker insert + malicious tags.

+
+ +
+ + http://openwall.com/lists/oss-security/2015/04/07/11 + https://hackerone.com/reports/46916 + http://danlec.com/blog/bug-in-sundown-and-redcarpet + + + 2015-04-07 + 2015-05-14 + +
+ phpMyAdmin -- XSRF and man-in-the-middle vulnerabilities