Skip to content

Commit 289856d

Browse files
jasnowRubySec CI
authored andcommitted
Updated advisory posts against rubysec/ruby-advisory-db@aee7a6e
1 parent afb32bd commit 289856d

File tree

1 file changed

+30
-0
lines changed

1 file changed

+30
-0
lines changed
Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
1+
---
2+
layout: advisory
3+
title: 'CVE-2023-25309 (rollout-ui): Cross Site Scripting (XSS) Vulnerability in Fetlife
4+
rollout-ui gem v0.5'
5+
comments: false
6+
categories:
7+
- rollout-ui
8+
advisory:
9+
gem: rollout-ui
10+
cve: 2023-25309
11+
ghsa: 5xq9-h3j2-jxvc
12+
url: https://github.com/advisories/GHSA-5xq9-h3j2-jxvc
13+
title: Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui gem v0.5
14+
date: 2023-05-23
15+
description: |
16+
Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui
17+
version 0.5, allows attackers to execute arbitrary code via a
18+
crafted url to the delete a **feature** functionality.
19+
cvss_v3: 6.1
20+
patched_versions:
21+
- ">= 0.5.3"
22+
related:
23+
url:
24+
- https://nvd.nist.gov/vuln/detail/CVE-2023-25309
25+
- https://github.com/fetlife/rollout-ui/releases/tag/v0.5.3
26+
- https://github.com/fetlife/rollout-ui/pull/15
27+
- https://github.com/fetlife/rollout-ui/pull/15/commits/6d202d2cbcae3dd9b92c1f5ab7be17b48d78c045
28+
- https://advisories.gitlab.com/pkg/gem/rollout-ui/CVE-2023-25309
29+
- https://github.com/advisories/GHSA-5xq9-h3j2-jxvc
30+
---

0 commit comments

Comments
 (0)