Bug 1177521 - (CVE-2020-8264) VUL-0: CVE-2020-8264: rubygem-actionpack-6.0: possible XSS vulnerability in Action Pack in development mode
(CVE-2020-8264)
VUL-0: CVE-2020-8264: rubygem-actionpack-6.0: possible XSS vulnerability in A...
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.3
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: Manuel Schnitzer
Security Team bot
https://smash.suse.de/issue/269031/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-10-09 11:15 UTC by Robert Frohl
Modified: 2020-10-16 15:34 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Frohl 2020-10-09 11:15:42 UTC
rh#1886554

There is a possible XSS vulnerability in Action Pack while the application server is in development mode. This vulnerability is in the Actionable Exceptions middleware.

Reference:
https://groups.google.com/g/rubyonrails-security/c/yQzUVfv42jk/m/oJWw-xhNAQAJ

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1886554
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-8264
Comment 1 Robert Frohl 2020-10-09 11:16:40 UTC
only affects rubygem-actionpack-6.0, older versions are not affected.

Only needed in openSUSE:Factory
Comment 2 Marcus Rückert 2020-10-16 15:34:59 UTC
created request id 842139
created request id 842140
created request id 842141
created request id 842142
created request id 842143
created request id 842144
created request id 842145
created request id 842146
created request id 842147
created request id 842148
created request id 842149
created request id 842150
created request id 842151