Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian 10: 2019-0775 Significant XSS Vulnerability in Ruby-Sinatra

fedora
Calendar Grey September 25, 2009
Dist Fedora Esm H88
A crucial update has been launched to fix a serious HTML injection vulnerability in Ruby on Rails for Fedora users. Download and install the new packages now
A vulnerability is found on Ruby on Rails in the escaping code for the form helpers, which also affects the rpms shipped in Fedora Project

Summary

Eases web-request routing, handling, and response as a half-way front,

half-way page controller. Implemented with specific emphasis on enabling easy

unit/integration testing that doesn't require a browser.

Update Information:

A vulnerability is found on Ruby on Rails in the escaping code for the form helpers, which also affects the rpms shipped in Fedora Project. Attackers who can inject deliberately malformed unicode strings into the form helpers can defeat the escaping checks and inject arbitrary HTML. This issue has been tagged as CVE-2009-3009. These new rpms will fix this issue.

Change Log

* Wed Sep 23 2009 Mamoru Tasaka - 2.3.3-2 - Patch for CVE-2009-3009 (bug 520843) * Tue Jul 28 2009 Jeroen van Meeuwen - 2.3.3-1 - New upstream version

References


[ 1 ] Bug #520843 - CVE-2009-3009 ruby-activesupport: XSS vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=520843

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update rubygem-actionpack' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: rubygem-actionpack
Product: Fedora 11
Version: 2.3.3
Release: 2.fc11
Summary: Web-flow and rendering framework putting the VC in MVC

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here