Bugzilla – Bug 1220646
VUL-0: CVE-2024-27285: rubygem-yard: XSS in generated frames.html of default YARD template
Last modified: 2024-07-03 05:22:10 UTC
YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. This vulnerability is fixed in 0.9.35. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-27285 https://www.cve.org/CVERecord?id=CVE-2024-27285 https://github.com/lsegal/yard/commit/2069e2bf08293bda2fcc78f7d0698af6354054be https://github.com/lsegal/yard/security/advisories/GHSA-8mq4-9jjh-9xrc
Relevant for SUSE:SLE-12-SP1:Update, Backports and Factory.