Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Debian DSA-4766-1 Moderate: Rails Security Update for XSS and Exploits

debian
Calendar Grey September 24, 2020
Debian Logo
An essential update for the Rails web framework has been released to tackle serious vulnerabilities, reducing risks associated with cross-site scripting (XSS) and unauthorized code execution.
Multiple security issues were discovered in the Rails web framework which could result in cross-site scripting, information leaks, code execution, cross-site request forgery or byp...

Summary

Multiple security issues were discovered in the Rails web framework
which could result in cross-site scripting, information leaks, code
execution, cross-site request forgery or bypass of upload limits.

For the stable distribution (buster), these problems have been fixed in
version 2:5.2.2.1+dfsg-1+deb10u2.

We recommend that you upgrade your rails packages.

For the detailed security status of rails please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/rails

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Package: rails
CVE ID: CVE-2020-8162 CVE-2020-8164 CVE-2020-8165 CVE-2020-8166

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here