redcarpet versions before 3.2.3 allow for possible XSS of untrusted markdown if autolink extension is enabled. Upstream fix: https://github.com/vmg/redcarpet/commit/e5a10516d07114d582d13b9125b733008c61c242 CVE request: http://www.openwall.com/lists/oss-security/2015/04/07/11
Created rubygem-redcarpet tracking bugs for this issue: Affects: fedora-all [bug 1209954] Affects: epel-all [bug 1209955]
CVE-2015-5147 was assigned to another issue in rubygem-redcarpet, which does not affect Fedora/EPEL packages: http://www.openwall.com/lists/oss-security/2015/06/30/10 Removing alias in this Bugzilla.
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.