Package        : ruby-rack
Version        : 1.5.2-3+deb8u2
CVE ID         : CVE-2018-16471
Debian Bug     : #913005

It was discovered that there was an XSS vulnerability in the ruby-rack
web-server library.

A malicious request could impact the HTTP/HTTPS scheme being returned
to the underlying application.

For Debian 8 "Jessie", this issue has been fixed in ruby-rack version
1.5.2-3+deb8u2.

We recommend that you upgrade your ruby-rack packages.


Regards,

- -- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org / chris-lamb.co.uk
       `-

Debian LTS: DLA-1585-1: ruby-rack security update

November 21, 2018
It was discovered that there was an XSS vulnerability in the ruby-rack web-server library

Summary

For Debian 8 "Jessie", this issue has been fixed in ruby-rack version
1.5.2-3+deb8u2.

We recommend that you upgrade your ruby-rack packages.


Regards,

- --
,''`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-



Severity
Package : ruby-rack
Version : 1.5.2-3+deb8u2
CVE ID : CVE-2018-16471
Debian Bug : #913005

Related News