HomeDefectsLIN1022-6829
Fixed

LIN1022-6829 : Security Advisory - yard - CVE-2024-27285

Created: Feb 28, 2024    Updated: Jul 27, 2025
Resolved Date: Jul 27, 2025
Found In Version: 10.22.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Userspace

Description

YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file.  This vulnerability is fixed in 0.9.35.

CREATE(Triage):(User=admin) CVE-2024-27285 (https://nvd.nist.gov/vuln/detail/CVE-2024-27285)