There is a possible XSS vulnerability in Rack before 2.0.6...
Vulnerability Description
There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value could be vulnerable to an XSS attack. Note that applications using the normal escaping mechanisms provided by Rails may not impacted, but applications that bypass the escaping mechanisms, or do not use them may be vulnerable.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-16471
Credits & Attribution
No credits recorded in the NVD database.
References
- https://groups.google.com/forum/#%21topic/rubyonrails-security/GKsAFT924Ag
- https://lists.debian.org/debian-lts-announce/2018/11/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00032.html
- https://usn.ubuntu.com/4089-1/
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00016.html
Affected Vendor
Rack
View all reports →