Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
All running applications using rh-ror41-rubygem-actionviewmust be restarted
for this update to take effect.
Ruby on Rails is a model-view-controller (MVC) framework for web
application development. Action View implements the view component.
Security Fix(es):
* It was discovered that Action View tag helpers did not escape quotes when
using strings declared as HTML safe as attribute values. A remote attacker
could use this flaw to conduct a cross-site scripting (XSS) attack.
(CVE-2016-6316)
Red Hat would like to thank the Ruby on Rails project for reporting this
issue. Upstream acknowledges Andrew Carpenter (Critical Juncture) as the
original reporter.
https://access.redhat.com/security/cve/CVE-2016-6316 https://access.redhat.com/security/updates/classification/#moderate
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6):
Source:
rh-ror41-rubygem-actionview-4.1.5-6.el6.src.rpm
noarch:
rh-ror41-rubygem-actionview-4.1.5-6.el6.noarch.rpm
rh-ror41-rubygem-actionview-doc-4.1.5-6.el6.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 6.6):
Source:
rh-ror41-rubygem-actionview-4.1.5-6.el6.src.rpm
noarch:
rh-ror41-rubygem-actionview-4.1.5-6.el6.noarch.rpm
rh-ror41-rubygem-actionview-doc-4.1.5-6.el6.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 6.7):
Source:
rh-ror41-rubygem-actionview-4.1.5-6.el6.src.rpm
noarch:
rh-ror41-rubygem-actionview-4.1.5-6.el6.noarch.rpm
rh-ror41-rubygem-actionview-doc-4.1.5-6.el6.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6):
Source:
rh-ror41-rubygem-actionview-4.1.5-6.el6.src.rpm
noarch:
rh-ror41-rubygem-actionview-4.1.5-6.el6.noarch.rpm
rh-ror41-rubygem-actionview-doc-4.1.5-6.el6.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):
Source:
rh-ror41-rubygem-actionview-4.1.5-6.el7.src.rpm
noarch:
rh-ror41-rubygem-actionview-4.1.5-6.el7.noarch.rpm
rh-ror41-rubygem-actionview-doc-4.1.5-6.el7.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.1):
Source:
Read the Full Advisory
An update for rh-ror41-rubygem-actionview is now available for Red HatSoftware Collections.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 6.6) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 6.7) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.1) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.2) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch
1365008 - CVE-2016-6316 rubygem-actionview: cross-site scripting flaw in Action View
Get the latest Linux and open source security news straight to your inbox.