|
| 1 | +--- |
| 2 | +gem: rubygems-update |
| 3 | +cve: 2018-1000078 |
| 4 | +ghsa: 87qx-g5wg-mwmj |
| 5 | +url: https://github.com/rubygems/rubygems/commit/66a28b9275551384fdab45f3591a82d6b59952cb |
| 6 | +title: RubyGems Cross-site Scripting vulnerability |
| 7 | +date: 2022-05-14 |
| 8 | +description: | |
| 9 | + RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: |
| 10 | + 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and |
| 11 | + earlier, prior to trunk revision 62422 contains a Cross Site Scripting (XSS) vulnerability |
| 12 | + in gem server display of homepage attribute that can result in XSS. This attack |
| 13 | + requires the victim to browse to a malicious gem on a vulnerable gem server. This |
| 14 | + vulnerability is fixed in 2.7.6. |
| 15 | +cvss_v3: 6.1 |
| 16 | +patched_versions: |
| 17 | +- ">= 2.7.6" |
| 18 | +related: |
| 19 | + url: |
| 20 | + - https://access.redhat.com/errata/RHSA-2018:3729 |
| 21 | + - https://access.redhat.com/errata/RHSA-2018:3730 |
| 22 | + - https://access.redhat.com/errata/RHSA-2018:3731 |
| 23 | + - https://access.redhat.com/errata/RHSA-2019:2028 |
| 24 | + - https://access.redhat.com/errata/RHSA-2020:0542 |
| 25 | + - https://access.redhat.com/errata/RHSA-2020:0591 |
| 26 | + - https://access.redhat.com/errata/RHSA-2020:0663 |
| 27 | + - https://lists.debian.org/debian-lts-announce/2018/04/msg00000.html |
| 28 | + - https://lists.debian.org/debian-lts-announce/2018/04/msg00001.html |
| 29 | + - https://lists.debian.org/debian-lts-announce/2018/04/msg00023.html |
| 30 | + - https://lists.debian.org/debian-lts-announce/2018/07/msg00012.html |
| 31 | + - https://lists.debian.org/debian-lts-announce/2019/05/msg00028.html |
| 32 | + - https://usn.ubuntu.com/3621-1/ |
| 33 | + - https://www.debian.org/security/2018/dsa-4219 |
| 34 | + - https://www.debian.org/security/2018/dsa-4259 |
| 35 | + - http://blog.rubygems.org/2018/02/15/2.7.6-released.html |
| 36 | + - http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html |
| 37 | + - https://github.com/jruby/jruby/commit/0b06b48ab4432237ce5fc1bef47f2c6bcf7843f7 |
| 38 | + - https://github.com/rubygems/rubygems/commit/5971b486d4dbb2bad5d3445b3801c456eb0ce183 |
0 commit comments