{"id":"openSUSE-SU-2021:0429-1","summary":"Security update for python-markdown2","details":"This update for python-markdown2 fixes the following issues:\n\nUpdate to 2.4.0 (boo#1181270):\n\n  - [pull #377] Fixed bug breaking strings elements in metadata lists\n  - [pull #380] When rendering fenced code blocks, also add the\n    language-LANG class\n  - [pull #387] Regex DoS fixes (CVE-2021-26813, boo#1183171)\n\n- Switch off failing tests (gh#trentm/python-markdown2#388),\n  ignore failing test suite.\n\nupdate to 2.3.9:\n\n  - [pull #335] Added header support for wiki tables\n  - [pull #336] Reset _toc when convert is run\n  - [pull #353] XSS fix\n  - [pull #350] XSS fix\n\n- Add patch to fix unsanitized input for cross-site scripting (boo#1171379)\n","modified":"2026-03-11T07:32:58.261199Z","published":"2021-03-16T17:08:32Z","related":["CVE-2021-26813"],"upstream":["CVE-2021-26813"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/3VPKRS46KKKFGLEDJJ7ZX2EZVNE5567H/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1171379"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181270"},{"type":"REPORT","url":"https://bugzilla.suse.com/1183171"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-26813"}],"affected":[{"package":{"name":"python-markdown2","ecosystem":"openSUSE:Leap 15.2","purl":"pkg:rpm/opensuse/python-markdown2&distro=openSUSE%20Leap%2015.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.0-lp152.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"python2-markdown2":"2.4.0-lp152.2.3.1","python3-markdown2":"2.4.0-lp152.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:0429-1.json"}}],"schema_version":"1.7.5"}