MGASA-2014-0054

Source
https://advisories.mageia.org/MGASA-2014-0054.html
Import Source
https://advisories.mageia.org/MGASA-2014-0054.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0054
Related
Published
2014-02-11T22:37:02Z
Modified
2014-02-11T22:36:58Z
Summary
Updated ruby-will_paginate package fixes CVE-2013-6459
Details

Updated ruby-willpaginate packages fix security vulnerability: Cross-Site Scripting (XSS) vulnerabilities were found in willpaginate gem for Ruby, where certain input related to generated pagination links were not properly sanitised before being returned. This could be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. (CVE-2013-6459).

References
Credits

Affected packages

Mageia:3 / ruby-will_paginate

Package

Name
ruby-will_paginate
Purl
pkg:rpm/mageia/ruby-will_paginate?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.3-3.1.mga3

Ecosystem specific

{
    "section": "core"
}