Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7689
HistoryNov 07, 2018 - 2:13 a.m.

Cross-site Scripting (XSS)

2018-11-0702:13:30
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.008 Low

EPSS

Percentile

81.7%

rack is vulnerable to cross-site scripting (XSS) attacks. The vulnerability exists due to the lack of sanitization on the data returned by the scheme method in Rack::Request, allowing XSS attacks.

CPENameOperatorVersion
rackle1.6.10
rackle2.0.5