RubySec

Providing security resources for the Ruby community

CVE-2023-3445 (spina): Spina Cross-site Scripting vulnerability

Spina Cross-site Scripting vulnerability

Published: June 28, 2023

SECURITY IDENTIFIERS

GEM

spina

SEVERITY

CVSS v3.x: 3.5 (Low)

PATCHED VERSIONS

>= 2.15.1

DESCRIPTION

Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1.

RELATED