There is a possible XSS vulnerability in Rack. Carefully crafted
requests can impact the data returned by the `scheme` method on
`Rack::Request`.Applications that expect the scheme to be limited to
"http" or "https" and do not escape the return value could be vulnerable
to an XSS attack (CVE-2018-16471).
- https://bugs.mageia.org/show_bug.cgi?id=23813
- https://www.openwall.com/lists/oss-security/2018/11/05/2
- https://www.cve.org/CVERecord?id=CVE-2018-16471
- 6/core/ruby-rack-1.6.11-1.mga6
Get the latest Linux and open source security news straight to your inbox.