[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195549

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2016:1855-01 -- Redhat rh-ror42-rubygem-actionpack, rh-ror42-rubygem-actionview, rh-ror42-rubygem-activerecord

ID: oval:org.secpod.oval:def:504870Date: (C)2021-02-03   (M)2022-10-10
Class: PATCHFamily: unix




Ruby on Rails is a model-view-controller framework for web application development. Action View implements the view component, and Active Record implements the model component. Security Fix in rubygem-actionview: * It was discovered that Action View tag helpers did not escape quotes when using strings declared as HTML safe as attribute values. A remote attacker could use this flaw to conduct a cross-site scripting attack. Security Fix in rubygem-activerecord: * A flaw was found in the way Active Record handled certain special values in dynamic finders and relations. If a Ruby on Rails application performed JSON parameter parsing, a remote attacker could possibly manipulate search conditions in SQL queries generated by the application. Red Hat would like to thank the Ruby on Rails project for reporting these issues. Upstream acknowledges Andrew Carpenter as the original reporter of CVE-2016-6316; and joernchen as the original reporter of CVE-2016-6317.

Platform:
Red Hat Enterprise Linux 7
Product:
rh-ror42-rubygem-actionpack
rh-ror42-rubygem-actionview
rh-ror42-rubygem-activerecord
Reference:
RHSA-2016:1855-01
CVE-2016-6316
CVE-2016-6317
CVE    2
CVE-2016-6316
CVE-2016-6317
CPE    4
cpe:/a:redhat:rh-ror42-rubygem-actionview
cpe:/o:redhat:enterprise_linux:7
cpe:/a:redhat:rh-ror42-rubygem-activerecord
cpe:/a:redhat:rh-ror42-rubygem-actionpack
...

© SecPod Technologies