rails_admin ruby gem XSS vulnerability
Published: March 14, 2020
SECURITY IDENTIFIERS
- CVE: CVE-2020-36190 (NVD)
- GHSA: GHSA-wjx2-7hqq-8h7m
- Vendor Advisory: https://github.com/sferik/rails_admin/commit/d72090ec6a07c3b9b7b48ab50f3d405f91ff4375
GEM
SEVERITY
CVSS v3.x: 6.1 (Medium)
PATCHED VERSIONS
~> 1.4.3
>= 2.0.2
DESCRIPTION
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms.
