DSA-2830-1 ruby-i18n -- cross-site scriptingID: oval:org.secpod.oval:def:601182 | Date: (C)2014-01-08 (M)2023-02-20 |
Class: PATCH | Family: unix |
Peter McLarnan discovered that the internationalization component of Ruby on Rails does not properly encode parameters in generated HTML code, resulting in a cross-site scripting vulnerability. This update corrects the underlying vulnerability in the i18n gem, as provided by the ruby-i18n package. The oldstable distribution is not affected by this problem; the libi18n-ruby package does not contain the vulnerable code.