rails_admin ruby gem XSS vulnerability
Moderate severity
GitHub Reviewed
Published
Jan 14, 2021
to the GitHub Advisory Database
•
Updated Jul 3, 2023
Package
Affected versions
>= 2.0.0, < 2.0.2
< 1.4.3
Patched versions
2.0.2
1.4.3
Description
Published by the National Vulnerability Database
Jan 12, 2021
Reviewed
Jan 14, 2021
Published to the GitHub Advisory Database
Jan 14, 2021
Last updated
Jul 3, 2023
RailsAdmin (aka rails_admin) before 1.4.3 and 2.x before 2.0.2 allows XSS via nested forms.
References