Updated ruby-rack packages fix security vulnerability
Publication date: 15 Nov 2018Modification date: 15 Nov 2018
Type: security
Affected Mageia releases : 6
CVE: CVE-2018-16471
Description
There is a possible XSS vulnerability in Rack. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`.Applications that expect the scheme to be limited to "http" or "https" and do not escape the return value could be vulnerable to an XSS attack (CVE-2018-16471).
References
SRPMS
6/core
- ruby-rack-1.6.11-1.mga6