Cisco Blog >Threat Research

Threat Research

Talos has discovered two XSS vulnerabilities in Ruby Rails Gems. Rails is a Ruby framework designed to create web services or web pages. Ruby Gems is a package manager for distributing software packages as 'gems'. The two XSS vulnerabilities were discovered in two different gem packages: delayed_job_web and rails_admin.

Ruby is widely used as a language for web development. Gem packages allow software engineers to reuse code across multiple development projects. As such, the discovery of a vulnerability in a gem may mean that many different systems are affected by that vulnerability.

Read More »

Tags:

Cisco Systems Inc. published this content on 10 January 2018 and is solely responsible for the information contained herein.
Distributed by Public, unedited and unaltered, on 10 January 2018 14:09:03 UTC.

Original documenthttps://blogs.cisco.com/security/talos/vulnerability-spotlight-ruby-rails-gem-xss-vulnerabilities

Public permalinkhttp://www.publicnow.com/view/2140E7711CED4CE20CA6BC3FD722092DB2D28B88