ADVISORIES
- CVE-2014-2538 (NVD)
- GHSA-v3rr-cph9-2g2q
- OSVDB-104734
GEM
SEVERITY
CVSS v2.0: 4.3 (Medium)
PATCHED VERSIONS
- >= 1.3.4
DESCRIPTION
Cross-site scripting (XSS) vulnerability in lib/rack/ssl.rb in the rack-ssl gem before 1.4.0 for Ruby allows remote attackers to inject arbitrary web script or HTML via a URI, which might not be properly handled by third-party adapters such as JRuby-Rack.