Wind River Support Network

HomeDefectsLIN1019-11229
Not to be fixed

LIN1019-11229 : Security Advisory - yard - CVE-2024-27285

Created: Feb 28, 2024    Updated: Apr 12, 2024
Resolved Date: Apr 12, 2024
Found In Version: 10.19.45.1
Severity: Standard
Applicable for: Wind River Linux LTS 19
Component/s: Userspace

Description

YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file.  This vulnerability is fixed in 0.9.35.

CREATE(Triage):(User=admin) CVE-2024-27285 (https://nvd.nist.gov/vuln/detail/CVE-2024-27285)
Live chat
Online