DSA-2260-1 rails -- severalID: oval:org.secpod.oval:def:600569 | Date: (C)2011-06-15 (M)2022-10-10 |
Class: PATCH | Family: unix |
Two vulnerabilities were discovered in Ruby on Rails, a web application framework. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-3086 The cookie store may be vulnerability to a timing attack, potentially allowing remote attackers to forge message digests. CVE-2009-4214 A cross-site scripting vulnerability in the strip_tags function allows remote user-assisted attackers to inject arbitrary web script.