Gemirro Stored XSS in Gemspec "homepage" value
Moderate severity
GitHub Reviewed
Published
Nov 29, 2017
to the GitHub Advisory Database
•
Updated Aug 29, 2023
Description
Published to the GitHub Advisory Database
Nov 29, 2017
Reviewed
Jun 16, 2020
Last updated
Aug 29, 2023
Stored cross-site scripting (XSS) vulnerability in Gemirro before 0.16.0 allows attackers to inject arbitrary web script via a crafted javascript: URL in the "homepage" value of a ".gemspec" file.
A ".gemspec" file must be created with a JavaScript URL in the homepage value. This can be used to build a gem for upload to the Gemirro server, in order to achieve stored XSS via the author name hyperlink.
References