VDB
Sign up
MEDIUM6.4

GHSA-r5jw-62xg-j433

Cross-Site Scripting in Kaminari

Quick fix

GHSA-r5jw-62xg-j433 — kaminari: upgrade to the fixed version with the command below.

bundle update kaminari

Details

### Impact In Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has been fixed in 1.2.1.

### Releases The 1.2.1 gem including the patch has already been released. All past released versions are affected by this vulnerability.

### Workarounds Application developers who can't update the gem can workaround by overriding the `PARAM_KEY_EXCEPT_LIST` constant.

```ruby module Kaminari::Helpers PARAM_KEY_EXCEPT_LIST = [:authenticity_token, :commit, :utf8, :_method, :script_name, :original_script_name].freeze end ```

### Credits Thanks to Daniel Mircea for finding the issue and sending a patch via GitHub. Also thanks to Aditya Prakash for reporting the vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/kaminari
Introduced in: 0Fixed in: 1.2.1
Fixbundle update kaminari

References