VDB
Sign up
MEDIUM6.1

GHSA-653m-r33x-39ff

Geminabox contains Cross-site Scripting

Quick fix

GHSA-653m-r33x-39ff — geminabox: upgrade to the fixed version with the command below.

bundle update geminabox

Details

Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/geminabox
Introduced in: 0Fixed in: 0.13.10
Fixbundle update geminabox

References