MEDIUM6.1
GHSA-653m-r33x-39ff
Geminabox contains Cross-site Scripting
Quick fix
GHSA-653m-r33x-39ff — geminabox: upgrade to the fixed version with the command below.
bundle update geminaboxDetails
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-16792[ADVISORY]
- https://github.com/geminabox/geminabox/commit/f8429a9e364658459add170e4ebc7a5d3b4759e7[WEB]
- https://github.com/geminabox/geminabox[PACKAGE]
- https://github.com/geminabox/geminabox/blob/master/CHANGELOG.md[WEB]
- https://rubygems.org/gems/geminabox/versions/0.13.10[WEB]