USN-6731-1
Dashboard / Vulnerabilities / USN-6731-1
USN-6731-1
Summary: yard vulnerabilities
Details: It was discovered that YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-17042) It was discovered that yard before 0.9.20 is affected by a path traversal vulnerability, allowing HTTP requests to access arbitrary files under certain conditions. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-1020001) Aviv Keller discovered that the "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. (CVE-2024-27285)
References: https://ubuntu.com/security/notices/USN-6731-1, https://ubuntu.com/security/CVE-2017-17042, https://ubuntu.com/security/CVE-2019-1020001, https://ubuntu.com/security/CVE-2024-27285
Affected packages
Package
Name: yard
Purl: pkg:deb/ubuntu/yard?arch=source&distro=esm-apps%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
