Sha256: f4679e2c6a44325e49201037501757e04fd3e56177258481f5ac186c2163844d
Contents?: true
Size: 1 KB
Versions: 19
Compression:
Stored size: 1 KB
Contents
module Dawn module Kb # Automatically created with rake on 2014-05-12 class CVE_2013_2105 include DependencyCheck def initialize message = "The Show In Browser (show_in_browser) gem 0.0.3 for Ruby allows local users to inject arbitrary web script or HTML via a symlink attack on /tmp/browser.html." super({ :name=>"CVE-2013-2105", :cvss=>"AV:L/AC:M/AU:N/C:N/I:P/A:P", :release_date => Date.new(2014, 4, 22), :cwe=>"59", :owasp=>"A9", :applies=>["sinatra", "padrino", "rails"], :kind=>Dawn::KnowledgeBase::DEPENDENCY_CHECK, :message=>message, :mitigation=>"Please upgrade show_in_browser version at least to 0.0.4. As a general rule, using the latest stable version is recommended.", :aux_links=>["http://xforce.iss.net/xforce/xfdb/84378"] }) self.safe_dependencies = [{:name=>"show_in_browser", :version=>['0.0.4']}] end end end end
Version data entries
19 entries across 19 versions & 1 rubygems