|
|
| |
|
| |
rubygem-rdoc: cross-site scripting
| Package(s): | rubygem-rdoc |
CVE #(s): | CVE-2013-0256
|
| Created: | February 15, 2013 |
Updated: | February 20, 2013 |
| Description: |
From the Ruby advisory:
RDoc documentation generated by rdoc bundled with ruby are vulnerable to an XSS exploit. All ruby users are recommended to update ruby to newer version which includes security-fixed RDoc. If you are publishing RDoc documentation generated by rdoc, you are recommended to apply a patch for the documentaion or re-generate it with security-fixed RDoc.
RDoc documentation generated by rdoc 2.3.0 through rdoc 3.12 and prereleases up to rdoc 4.0.0.preview2.1 are vulnerable to an XSS exploit. This exploit may lead to cookie disclosure to third parties. |
| Alerts: |
|
( Log in to post comments)
|
|
|