UNKNOWN RubyGems

RDoc contains XSS vulnerability

GHSA-v2r9-c84j-v7xm · CVE-2013-0256

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.

Ready to move

Start Securing

Free, no credit card | First findings in minutes