YARD is a documentation generation tool for the Ruby programming language. It enables the user to generate consistent, usable documentation that can be exported to a number of formats very easily, and also supports extending for custom Ruby constructs such as custom class level definitions.
Security Fix(es):
YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. This vulnerability is fixed in 0.9.36.(CVE-2024-27285)
{ "severity": "Medium" }
{ "noarch": [ "rubygem-yard-0.9.26-3.oe2203.noarch.rpm", "rubygem-yard-doc-0.9.26-3.oe2203.noarch.rpm", "rubygem-yard-0.9.26-3.oe2203sp1.noarch.rpm", "rubygem-yard-doc-0.9.26-3.oe2203sp1.noarch.rpm", "rubygem-yard-0.9.26-3.oe2203sp2.noarch.rpm", "rubygem-yard-doc-0.9.26-3.oe2203sp2.noarch.rpm", "rubygem-yard-0.9.26-3.oe2203sp3.noarch.rpm", "rubygem-yard-doc-0.9.26-3.oe2203sp3.noarch.rpm" ], "src": [ "rubygem-yard-0.9.26-3.oe2203.src.rpm", "rubygem-yard-0.9.26-3.oe2203sp1.src.rpm", "rubygem-yard-0.9.26-3.oe2203sp2.src.rpm", "rubygem-yard-0.9.26-3.oe2203sp3.src.rpm" ] }