UBUNTU-CVE-2024-27285
Dashboard / Vulnerabilities / UBUNTU-CVE-2024-27285
UBUNTU-CVE-2024-27285
Summary:
Details: YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. This vulnerability is fixed in 0.9.36.
References: https://ubuntu.com/security/CVE-2024-27285, https://github.com/lsegal/yard/security/advisories/GHSA-8mq4-9jjh-9xrc, https://github.com/lsegal/yard/commit/d78fc393d603c4fc35975969296ed381146a29d4, https://github.com/lsegal/yard/commit/c88406e4b78f8dd4ba38c79eea0bcec716dbbef8, https://github.com/lsegal/yard/commit/2a0b9990b64ceeeb0456177c593e36e204a06df1, https://github.com/lsegal/yard/commit/a831a596b2a7cabdd2e17855dd179af2ebf3d559, https://github.com/lsegal/yard/commit/2069e2bf08293bda2fcc78f7d0698af6354054be, https://www.cve.org/CVERecord?id=CVE-2024-27285, https://ubuntu.com/security/notices/USN-6731-1
Affected packages
Package
Name: yard
Purl: pkg:deb/ubuntu/[email protected]+git20160220-3ubuntu0.1~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
