Launch Week Day 1: Announcing Security Design Review
LOW 3.5 RubyGems

Cross-site Scripting in actionpack

GHSA-9chr-4fjh-5rgw

Published ยท Modified

Description

actionpack from the Ruby on Rails project is vulnerable to Cross-site Scripting in the Route Error Page. This issue has been patched with this commit.

This vulnerability is disputed by the Rails security team. It requires that the developer is tricked into copy pasting a malicious javascript-containing string into a development-only error page accessible only via localhost.

Ready to move

Start Securing

Free, no credit card | First findings in minutes