Red Hat Security Advisory 2016-1855-01

Discussion in 'News Aggregator' started by Packet Storm, 14 Sep 2016.

  1. Packet Storm

    Packet Storm Guest

    Red Hat Security Advisory 2016-1855-01 - Ruby on Rails is a model-view-controller framework for web application development. Action View implements the view component, and Active Record implements the model component. Security Fix in rubygem-actionview: It was discovered that Action View tag helpers did not escape quotes when using strings declared as HTML safe as attribute values. A remote attacker could use this flaw to conduct a cross-site scripting attack.

    Continue reading...
     

Share This Page

Loading...