Mageia 2018-0449: ruby-rack security update
Summary
There is a possible XSS vulnerability in Rack. Carefully crafted
requests can impact the data returned by the `scheme` method on
`Rack::Request`.Applications that expect the scheme to be limited to
"http" or "https" and do not escape the return value could be vulnerable
to an XSS attack (CVE-2018-16471).
References
- https://bugs.mageia.org/show_bug.cgi?id=23813
- https://www.openwall.com/lists/oss-security/2018/11/05/2
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16471
Resolution
MGASA-2018-0449 - Updated ruby-rack packages fix security vulnerability
SRPMS
- 6/core/ruby-rack-1.6.11-1.mga6