MGASA-2014-0054

Source
https://advisories.mageia.org/MGASA-2014-0054.html
Import Source
https://advisories.mageia.org/MGASA-2014-0054.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0054
Upstream
Published
2014-02-11T22:37:02Z
Modified
2026-04-16T06:23:18Z
Summary
Updated ruby-will_paginate package fixes CVE-2013-6459
Details

Updated ruby-will_paginate packages fix security vulnerability: Cross-Site Scripting (XSS) vulnerabilities were found in will_paginate gem for Ruby, where certain input related to generated pagination links were not properly sanitised before being returned. This could be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. (CVE-2013-6459).

References
Credits

Affected packages

Mageia:3 / ruby-will_paginate

Package

Name
ruby-will_paginate
Purl
pkg:rpm/mageia/ruby-will_paginate?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.3-3.1.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2014-0054.json"