Closed stanhu closed 3 years ago
Thanks! I think this makes sense also from a security point of view.
@gettalong Thanks! Would you mind merging and tagging a new release?
There will be a release in due time.
Thank you - merged and will be in the upcoming release.
Source of CVSS 9.9 in GitLab.
I see no reason to keep it disconnected/under wraps once the patch (and consequently the vector) is known.
this issue got CVE-2021-28834 assigned
ff0218aefcf00cd5a389e17e075d36cd46d011e2 added support for specifying custom Rouge formatters with the constraint that the formatter be in the
Rouge::Formatters
namespace, but it did not actually enforce this constraint. For example, this is valid:Adding the
false
parameter toconst_get
prevents this: