Lucene search

K
redhatRedHatRHSA-2016:1858
HistorySep 13, 2016 - 9:51 a.m.

(RHSA-2016:1858) Moderate: ruby193-rubygem-actionpack security update

2016-09-1309:51:35
access.redhat.com
16

0.003 Low

EPSS

Percentile

69.9%

Ruby on Rails is a model-view-controller (MVC) framework for web application development. Action Pack implements the controller and the view components.

Security Fix(es):

  • It was discovered that Action View tag helpers did not escape quotes when using strings declared as HTML safe as attribute values. A remote attacker could use this flaw to conduct a cross-site scripting (XSS) attack. (CVE-2016-6316)

Red Hat would like to thank the Ruby on Rails project for reporting this issue. Upstream acknowledges Andrew Carpenter (Critical Juncture) as the original reporter.