SUSE alert openSUSE-SU-2025:15119-1 (ruby3.4-rubygem-kramdown)
| From: | meissner@suse.com | |
| To: | security-announce@lists.opensuse.org | |
| Subject: | openSUSE-SU-2025:15119-1: moderate: ruby3.4-rubygem-kramdown-2.4.0-1.15 on GA media | |
| Date: | Sun, 18 May 2025 17:36:11 +0200 | |
| Message-ID: | <20250518153611.88993FD85@maintenance.suse.de> | |
| Archive-link: | Article |
# ruby3.4-rubygem-kramdown-2.4.0-1.15 on GA media Announcement ID: openSUSE-SU-2025:15119-1 Rating: moderate Cross-References: * CVE-2020-14001 * CVE-2021-28834 CVSS scores: * CVE-2020-14001 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2021-28834 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Tumbleweed An update that solves 2 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the ruby3.4-rubygem-kramdown-2.4.0-1.15 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * ruby3.4-rubygem-kramdown 2.4.0-1.15 ## References: * https://www.suse.com/security/cve/CVE-2020-14001.html * https://www.suse.com/security/cve/CVE-2021-28834.html
