• [SECURITY] [DSA 5389-1] rails security update

    Debian Security Advisory DSA-5389-1
Aron Xu
April 14, 2023
    April 14, 2023 https://www.debian.org/security/faq
    

    Package : rails
    CVE ID : CVE-2023-23913 CVE-2023-28120
    Debian Bug : 1033262 1033263

    Brief introduction

    Two vulnerabilities were discovered in rails, the Ruby based server-side
    MVC web application framework, which could lead to XSS and DOM based
    cross-site scripting (CRS).

    This update also fixes a regression introduced in previous update that
    may block certain access for apps using development environment.

    For the stable distribution (bullseye), these problems have been fixed in version 2:

    We recommend that you upgrade your rails packages.

    For the detailed security status of rails please refer to
    its security tracker page at:

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: debian-security-announce@lists.debian.org

