CVE-2024-27285
MEDIUM 6.1EPSS 1.1%
YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. This vulnerability is fixed in 0.9.36.
- CVSS v3.1
- 6.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - CVSS v3.1
- 5.4 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N - CVSS v3.1
- 5.4 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N - EPSS
- 1.06% chance of exploitation in the next 30 days, 62th percentile
- Published
- 2024-02-28
- Updated
- 2025-02-13
Proof-of-concept exploits (3)
- lsegal/yard/security/advisories/GHSA-8mq4-9jjh-9xrc
- rubysec/ruby-advisory-db/blob/master/gems/yard/CVE-2024-27285.yml
- advisories/GHSA-8mq4-9jjh-9xrc