MEDIUM6.1
GHSA-3j95-fjv2-3m4p
CSS Injection in Chartkick gem
Quick fix
GHSA-3j95-fjv2-3m4p — chartkick: upgrade to the fixed version with the command below.
bundle update chartkickDetails
The Chartkick gem through 3.3.2 for Ruby allows Cascading Style Sheets (CSS) Injection (without attribute).
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-16254[ADVISORY]
- https://github.com/ankane/chartkick/issues/546[WEB]
- https://github.com/ankane/chartkick/commit/ba67ab5e603de4d94676790fdac425f8199f1c4f[WEB]
- https://github.com/ankane/chartkick[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/chartkick/CVE-2020-16254.yml[WEB]