File tree Expand file tree Collapse file tree 1 file changed +30
-0
lines changed
Expand file tree Collapse file tree 1 file changed +30
-0
lines changed Original file line number Diff line number Diff line change 1+ ---
2+ layout : advisory
3+ title : ' CVE-2023-25309 (rollout-ui): Cross Site Scripting (XSS) Vulnerability in Fetlife
4+ rollout-ui gem v0.5'
5+ comments : false
6+ categories :
7+ - rollout-ui
8+ advisory :
9+ gem : rollout-ui
10+ cve : 2023-25309
11+ ghsa : 5xq9-h3j2-jxvc
12+ url : https://github.com/advisories/GHSA-5xq9-h3j2-jxvc
13+ title : Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui gem v0.5
14+ date : 2023-05-23
15+ description : |
16+ Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui
17+ version 0.5, allows attackers to execute arbitrary code via a
18+ crafted url to the delete a **feature** functionality.
19+ cvss_v3 : 6.1
20+ patched_versions :
21+ - " >= 0.5.3"
22+ related :
23+ url :
24+ - https://nvd.nist.gov/vuln/detail/CVE-2023-25309
25+ - https://github.com/fetlife/rollout-ui/releases/tag/v0.5.3
26+ - https://github.com/fetlife/rollout-ui/pull/15
27+ - https://github.com/fetlife/rollout-ui/pull/15/commits/6d202d2cbcae3dd9b92c1f5ab7be17b48d78c045
28+ - https://advisories.gitlab.com/pkg/gem/rollout-ui/CVE-2023-25309
29+ - https://github.com/advisories/GHSA-5xq9-h3j2-jxvc
30+ ---
You can’t perform that action at this time.
0 commit comments