YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. This vulnerability is fixed in 0.9.36.
History

Fri, 14 Feb 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Debian
Debian debian Linux
Fedoraproject
Fedoraproject fedora
CPEs cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
Vendors & Products Debian
Debian debian Linux
Fedoraproject
Fedoraproject fedora

Thu, 13 Feb 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Yardoc
Yardoc yard
CPEs cpe:2.3:a:yardoc:yard:*:*:*:*:*:*:*:*
Vendors & Products Yardoc
Yardoc yard
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-02-13T17:46:21.796Z

Reserved: 2024-02-22T18:08:38.872Z

Link: CVE-2024-27285

cve-icon Vulnrichment

Updated: 2024-08-02T00:28:00.247Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-28T20:15:41.940

Modified: 2025-02-14T15:31:24.213

Link: CVE-2024-27285

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-02-28T00:00:00Z

Links: CVE-2024-27285 - Bugzilla