CVE-2020-8264
06.01.2021, 21:15
In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or embed (in another page) a specially crafted URL which can allow the attacker to execute JavaScript in the context of the local application. This vulnerability is in the Actionable Exceptions middleware.
Vendor | Product | Version |
---|---|---|
rubyonrails | rails | 6.0.0 ≤ 𝑥 < 6.0.3.4 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||
---|---|---|---|---|---|---|---|---|---|
rails |
| ||||||||
rails-4.0 |
| ||||||||
ruby-actionpack-3.2 |
| ||||||||
ruby-activemodel-3.2 |
| ||||||||
ruby-activerecord-3.2 |
| ||||||||
ruby-activesupport-3.2 |
| ||||||||
ruby-rails-3.2 |
|