Debian: 2830-1: ruby-i18n: cross-site scripting

Posted by Ridcully on Jan 1, 2014 4:32 AM EDT
LinuxSecurity.com; By Benjamin D. Thomas
Mail this story
Print this story

Peter McLarnan discovered that the internationalization component of Ruby on Rails does not properly encode parameters in generated HTML code, resulting in a cross-site scripting vulnerability. This update corrects the underlying vulnerability in the i18n gem, as provided by the ruby-i18n package.

Full Story

  Nav
» Read more about: Story Type: News Story, Security; Groups: Debian, Developer, Ruby

« Return to the newswire homepage

This topic does not have any threads posted yet!

You cannot post until you login.