YARD is a documentation generation tool for the Ruby programming language. It enables the user to generate consistent, usable documentation that can be exported to a number of formats very easily, and also supports extending for custom Ruby constructs such as custom class level definitions.
Security Fix(es):
YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. This vulnerability is fixed in 0.9.36.(CVE-2024-27285)
{
"severity": "Medium"
}{
"noarch": [
"rubygem-yard-0.9.26-3.oe2203.noarch.rpm",
"rubygem-yard-doc-0.9.26-3.oe2203.noarch.rpm",
"rubygem-yard-0.9.26-3.oe2203sp1.noarch.rpm",
"rubygem-yard-doc-0.9.26-3.oe2203sp1.noarch.rpm",
"rubygem-yard-0.9.26-3.oe2203sp2.noarch.rpm",
"rubygem-yard-doc-0.9.26-3.oe2203sp2.noarch.rpm",
"rubygem-yard-0.9.26-3.oe2203sp3.noarch.rpm",
"rubygem-yard-doc-0.9.26-3.oe2203sp3.noarch.rpm"
],
"src": [
"rubygem-yard-0.9.26-3.oe2203.src.rpm",
"rubygem-yard-0.9.26-3.oe2203sp1.src.rpm",
"rubygem-yard-0.9.26-3.oe2203sp2.src.rpm",
"rubygem-yard-0.9.26-3.oe2203sp3.src.rpm"
]
}