Skip to content

Commit aee7a6e

Browse files
authored
GHSA SYNC: 1 brand new advisory (#963)
1 parent 01befbb commit aee7a6e

File tree

1 file changed

+22
-0
lines changed

1 file changed

+22
-0
lines changed

gems/rollout-ui/CVE-2023-25309.yml

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
---
2+
gem: rollout-ui
3+
cve: 2023-25309
4+
ghsa: 5xq9-h3j2-jxvc
5+
url: https://github.com/advisories/GHSA-5xq9-h3j2-jxvc
6+
title: Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui gem v0.5
7+
date: 2023-05-23
8+
description: |
9+
Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui
10+
version 0.5, allows attackers to execute arbitrary code via a
11+
crafted url to the delete a **feature** functionality.
12+
cvss_v3: 6.1
13+
patched_versions:
14+
- ">= 0.5.3"
15+
related:
16+
url:
17+
- https://nvd.nist.gov/vuln/detail/CVE-2023-25309
18+
- https://github.com/fetlife/rollout-ui/releases/tag/v0.5.3
19+
- https://github.com/fetlife/rollout-ui/pull/15
20+
- https://github.com/fetlife/rollout-ui/pull/15/commits/6d202d2cbcae3dd9b92c1f5ab7be17b48d78c045
21+
- https://advisories.gitlab.com/pkg/gem/rollout-ui/CVE-2023-25309
22+
- https://github.com/advisories/GHSA-5xq9-h3j2-jxvc

0 commit comments

Comments
 (0)