CVE-2024-27285

CVSS V2 None CVSS V3 None
Description
YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. This vulnerability is fixed in 0.9.36.
Overview
  • CVE ID
  • CVE-2024-27285
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-02-28T19:22:15.026Z
  • Last Modified Date
  • 2024-03-01T16:48:05.346Z
History
Created Old Value New Value Data Type Notes
2024-06-26 01:48:59 Added to TrackCVE