CVE-2014-2538 rubygem rack-ssl: URL error display XSS
Published: July 09, 2013
SECURITY IDENTIFIERS
- CVE: CVE-2014-2538 (NVD)
- GHSA: GHSA-v3rr-cph9-2g2q
- OSVDB: OSVDB-104734
GEM
SEVERITY
CVSS v2.0: 4.3 (Medium)
PATCHED VERSIONS
>= 1.3.4
DESCRIPTION
Cross-site scripting (XSS) vulnerability in lib/rack/ssl.rb in the rack-ssl gem before 1.4.0 for Ruby allows remote attackers to inject arbitrary web script or HTML via a URI, which might not be properly handled by third-party adapters such as JRuby-Rack.
