MEDIUM6.1
GHSA-wjx2-7hqq-8h7m
rails_admin ruby gem XSS vulnerability
Quick fix
GHSA-wjx2-7hqq-8h7m — rails_admin: upgrade to the fixed version with the command below.
bundle update rails_adminDetails
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-36190[ADVISORY]
- https://github.com/sferik/rails_admin/commit/d72090ec6a07c3b9b7b48ab50f3d405f91ff4375[WEB]
- https://github.com/railsadminteam/rails_admin[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rails_admin/CVE-2020-36190.yml[WEB]
- https://github.com/sferik/rails_admin/blob/master/README.md[WEB]
- https://github.com/sferik/rails_admin/compare/v1.4.2...v1.4.3[WEB]