Debian Security Advisory
DLA-1585-1 ruby-rack -- LTS security update
- Date Reported:
- 21 Nov 2018
- Affected Packages:
- ruby-rack
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2018-16471.
- More information:
-
It was discovered that there was an XSS vulnerability in the ruby-rack web-server library.
A malicious request could impact the HTTP/HTTPS scheme being returned to the underlying application.
For Debian 8
Jessie
, this issue has been fixed in ruby-rack version 1.5.2-3+deb8u2.We recommend that you upgrade your ruby-rack packages.