Debian Security Advisory

DLA-1585-1 ruby-rack -- LTS security update

Date Reported:
21 Nov 2018
Affected Packages:
ruby-rack
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2018-16471.
More information:

It was discovered that there was an XSS vulnerability in the ruby-rack web-server library.

A malicious request could impact the HTTP/HTTPS scheme being returned to the underlying application.

For Debian 8 Jessie, this issue has been fixed in ruby-rack version 1.5.2-3+deb8u2.

We recommend that you upgrade your ruby-rack packages.