Advisories ยป MGASA-2018-0449

Updated ruby-rack packages fix security vulnerability

Publication date: 15 Nov 2018
Modification date: 15 Nov 2018
Type: security
Affected Mageia releases : 6
CVE: CVE-2018-16471

Description

There is a possible XSS vulnerability in Rack.  Carefully crafted
requests can impact the data returned by the `scheme` method on
`Rack::Request`.Applications that expect the scheme to be limited to
"http" or "https" and do not escape the return value could be vulnerable
to an XSS attack (CVE-2018-16471).
                

References

SRPMS

6/core