CVE-2020-8264
06.01.2021, 21:15
In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or embed (in another page) a specially crafted URL which can allow the attacker to execute JavaScript in the context of the local application. This vulnerability is in the Actionable Exceptions middleware.
| Vendor | Product | Version |
|---|---|---|
| rubyonrails | rails | 6.0.0 ≤ 𝑥 < 6.0.3.4 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| rails |
| ||||||||
| rails-4.0 |
| ||||||||
| ruby-actionpack-3.2 |
| ||||||||
| ruby-activemodel-3.2 |
| ||||||||
| ruby-activerecord-3.2 |
| ||||||||
| ruby-activesupport-3.2 |
| ||||||||
| ruby-rails-3.2 |
|