NA

CVE-2023-28362

Vulnerability Summary

Description<!---->A Cross-site Scripting (XSS) vulnerability was found in Actionpack due to improper sanitization of user-supplied values. This allows provided values to contain characters that are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned location header.A Cross-site Scripting (XSS) vulnerability was found in Actionpack due to improper sanitization of user-supplied values. This allows provided values to contain characters that are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove the assigned location header.

Vendor Advisories

概述 Moderate: Satellite 6141 Async Security Update 类型/严重性 Security Advisory: Moderate Red Hat Insights 补丁分析 识别并修复受此公告影响的系统。 查看受影响的系统 标题 Updated Satellite 614 packages that fixes Important security bugs and severalregular bugs are now available for Red Hat Sate ...
Debian Bug report logs - #1051058 rails: CVE-2023-28362 Package: src:rails; Maintainer for src:rails is Debian Ruby Team &lt;pkg-ruby-extras-maintainers@listsaliothdebianorg&gt;; Reported by: Salvatore Bonaccorso &lt;carnil@debianorg&gt; Date: Fri, 1 Sep 2023 20:48:01 UTC Severity: important Tags: security, upstream Found ...
Description<!---->A Cross-site Scripting (XSS) vulnerability was found in Actionpack due to improper sanitization of user-supplied values This allows provided values to contain characters that are not legal in an HTTP header value This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove ...