ZeroHour

CVE-2024-27285

PoC ×2
CVSS 3.1
6.1 medium
EPSS
1%p63
Published
()
Modified
Description

YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. This vulnerability is fixed in 0.9.36.

Vendors
yardocfedoraprojectdebian
Products
yard, fedora, debian linux
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.