VDB
Sign up
MEDIUM

GHSA-v2r9-c84j-v7xm

RDoc contains XSS vulnerability

Quick fix

GHSA-v2r9-c84j-v7xm — rdoc: upgrade to the fixed version with the command below.

bundle update rdoc

Details

darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/rdoc
Introduced in: 2.3.0Fixed in: 3.12.1
Fixbundle update rdoc

References