OSV 1.4.0 · github-reviewed · 修改于 2023-08-29 20:26
发布时间
2017-11-30 07:19
GitHub 审查时间
2020-06-17 06:02
NVD 发布时间
—
源文件
advisories/github-reviewed/2017/11/GHSA-x7p2-x2j6-mwhr/GHSA-x7p2-x2j6-mwhr.json
Stored cross-site scripting (XSS) vulnerability in Gemirro before 0.16.0 allows attackers to inject arbitrary web script via a crafted javascript: URL in the "homepage" value of a ".gemspec" file. A ".gemspec" file must be created with a JavaScript URL in the homepage value. This can be used to build a gem for upload to the Gemirro server, in order to achieve stored XSS via the author name hyperlink.