MEDIUM6.1
GHSA-fj2w-qmjp-3rjm
Gollum Cross-site Scripting vulnerability via filename parameter to New Page dialog
Quick fix
GHSA-fj2w-qmjp-3rjm — gollum: upgrade to the fixed version with the command below.
bundle update gollumDetails
Cross site scripting (XSS) in gollum 5.0 to 5.1.2 via the filename parameter to the 'New Page' dialog.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-35305[ADVISORY]
- https://github.com/gollum/gollum/commit/137728cdabc0f60859fcd30404ad2b8fff6ef715[WEB]
- https://github.com/Szarny[WEB]
- https://github.com/gollum[WEB]
- https://github.com/gollum/gollum[PACKAGE]
- https://github.com/gollum/gollum/releases/tag/v5.1.2[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/gollum/CVE-2020-35305.yml[WEB]
- http://gollum.com[WEB]