MEDIUM
GHSA-v2r9-c84j-v7xm
RDoc contains XSS vulnerability
Quick fix
GHSA-v2r9-c84j-v7xm — rdoc: upgrade to the fixed version with the command below.
bundle update rdocDetails
darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2013-0256[ADVISORY]
- https://github.com/rdoc/rdoc/commit/ffa87887ee0517793df7541629a470e331f9fe60[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=907820[WEB]
- https://github.com/advisories/GHSA-v2r9-c84j-v7xm[ADVISORY]
- https://github.com/rdoc/rdoc[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rdoc/CVE-2013-0256.yml[WEB]
- https://web.archive.org/web/20130402173730/http://blog.segment7.net:80/2013/02/06/rdoc-xss-vulnerability-cve-2013-0256-releases-3-9-5-3-12-1-4-0-0-rc-2[WEB]
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00015.html[WEB]
- http://lists.opensuse.org/opensuse-updates/2013-02/msg00048.html[WEB]
- http://rhn.redhat.com/errata/RHSA-2013-0686.html[WEB]
- http://rhn.redhat.com/errata/RHSA-2013-0701.html[WEB]
- http://rhn.redhat.com/errata/RHSA-2013-0728.html[WEB]
- http://www.ruby-lang.org/en/news/2013/02/06/rdoc-xss-cve-2013-0256[WEB]
- http://www.ubuntu.com/usn/USN-1733-1[WEB]