VDB
Sign up
MEDIUM5.4

GHSA-98hq-3qvg-pg78

Gem in a Box vulnerable to Cross-site Scripting

Quick fix

GHSA-98hq-3qvg-pg78 — geminabox: upgrade to the fixed version with the command below.

bundle update geminabox

Details

geminabox (aka Gem in a Box) before 0.13.6 is vulnerable to Cross-site Scripting (XSS), as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/geminabox
Introduced in: 0Fixed in: 0.13.6
Fixbundle update geminabox

References