Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Debian Security Advisory DSA-5389-1 Addresses Critical XSS in Rails

debian
Calendar Grey April 14, 2023
Debian Logo
Enhance your Debian system's security against XSS and DOM vulnerabilities by upgrading Rails following these steps for patch DSA-5389-1, issued April 14, 2023
Brief introduction Two vulnerabilities were discovered in rails, the Ruby based server-side MVC web application framework, which could lead to XSS and DOM based

Summary

Two vulnerabilities were discovered in rails, the Ruby based server-side
MVC web application framework, which could lead to XSS and DOM based
cross-site scripting (CRS).

This update also fixes a regression introduced in previous update that
may block certain access for apps using development environment.

For the stable distribution (bullseye), these problems have been fixed in
version 2:6.0.3.7+dfsg-2+deb11u2.

We recommend that you upgrade your rails packages.

For the detailed security status of rails please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/rails

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: rails
CVE ID: CVE-2023-23913 CVE-2023-28120

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here