There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.
{
    "binaries": [
        {
            "binary_version": "2:6.1.7.3+dfsg-3",
            "binary_name": "rails"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-3",
            "binary_name": "ruby-actioncable"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-3",
            "binary_name": "ruby-actionmailbox"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-3",
            "binary_name": "ruby-actionmailer"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-3",
            "binary_name": "ruby-actionpack"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-3",
            "binary_name": "ruby-actiontext"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-3",
            "binary_name": "ruby-actionview"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-3",
            "binary_name": "ruby-activejob"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-3",
            "binary_name": "ruby-activemodel"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-3",
            "binary_name": "ruby-activerecord"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-3",
            "binary_name": "ruby-activestorage"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-3",
            "binary_name": "ruby-activesupport"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-3",
            "binary_name": "ruby-rails"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-3",
            "binary_name": "ruby-railties"
        }
    ]
}{
    "binaries": [
        {
            "binary_version": "2:6.1.7.3+dfsg-7",
            "binary_name": "rails"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-7",
            "binary_name": "ruby-actioncable"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-7",
            "binary_name": "ruby-actionmailbox"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-7",
            "binary_name": "ruby-actionmailer"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-7",
            "binary_name": "ruby-actionpack"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-7",
            "binary_name": "ruby-actiontext"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-7",
            "binary_name": "ruby-actionview"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-7",
            "binary_name": "ruby-activejob"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-7",
            "binary_name": "ruby-activemodel"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-7",
            "binary_name": "ruby-activerecord"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-7",
            "binary_name": "ruby-activestorage"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-7",
            "binary_name": "ruby-activesupport"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-7",
            "binary_name": "ruby-rails"
        },
        {
            "binary_version": "2:6.1.7.3+dfsg-7",
            "binary_name": "ruby-railties"
        }
    ]
}{
    "binaries": [
        {
            "binary_version": "2:7.2.2.1+dfsg-7",
            "binary_name": "rails"
        },
        {
            "binary_version": "2:7.2.2.1+dfsg-7",
            "binary_name": "ruby-actioncable"
        },
        {
            "binary_version": "2:7.2.2.1+dfsg-7",
            "binary_name": "ruby-actionmailbox"
        },
        {
            "binary_version": "2:7.2.2.1+dfsg-7",
            "binary_name": "ruby-actionmailer"
        },
        {
            "binary_version": "2:7.2.2.1+dfsg-7",
            "binary_name": "ruby-actionpack"
        },
        {
            "binary_version": "2:7.2.2.1+dfsg-7",
            "binary_name": "ruby-actiontext"
        },
        {
            "binary_version": "2:7.2.2.1+dfsg-7",
            "binary_name": "ruby-actionview"
        },
        {
            "binary_version": "2:7.2.2.1+dfsg-7",
            "binary_name": "ruby-activejob"
        },
        {
            "binary_version": "2:7.2.2.1+dfsg-7",
            "binary_name": "ruby-activemodel"
        },
        {
            "binary_version": "2:7.2.2.1+dfsg-7",
            "binary_name": "ruby-activerecord"
        },
        {
            "binary_version": "2:7.2.2.1+dfsg-7",
            "binary_name": "ruby-activestorage"
        },
        {
            "binary_version": "2:7.2.2.1+dfsg-7",
            "binary_name": "ruby-activesupport"
        },
        {
            "binary_version": "2:7.2.2.1+dfsg-7",
            "binary_name": "ruby-rails"
        },
        {
            "binary_version": "2:7.2.2.1+dfsg-7",
            "binary_name": "ruby-railties"
        }
    ]
}{
    "binaries": [
        {
            "binary_version": "2:4.2.6-1ubuntu0.1~esm2",
            "binary_name": "rails"
        },
        {
            "binary_version": "2:4.2.6-1ubuntu0.1~esm2",
            "binary_name": "ruby-actionmailer"
        },
        {
            "binary_version": "2:4.2.6-1ubuntu0.1~esm2",
            "binary_name": "ruby-actionpack"
        },
        {
            "binary_version": "2:4.2.6-1ubuntu0.1~esm2",
            "binary_name": "ruby-actionview"
        },
        {
            "binary_version": "2:4.2.6-1ubuntu0.1~esm2",
            "binary_name": "ruby-activejob"
        },
        {
            "binary_version": "2:4.2.6-1ubuntu0.1~esm2",
            "binary_name": "ruby-activemodel"
        },
        {
            "binary_version": "2:4.2.6-1ubuntu0.1~esm2",
            "binary_name": "ruby-activerecord"
        },
        {
            "binary_version": "2:4.2.6-1ubuntu0.1~esm2",
            "binary_name": "ruby-activesupport"
        },
        {
            "binary_version": "2:4.2.6-1ubuntu0.1~esm2",
            "binary_name": "ruby-rails"
        },
        {
            "binary_version": "2:4.2.6-1ubuntu0.1~esm2",
            "binary_name": "ruby-railties"
        }
    ]
}{
    "binaries": [
        {
            "binary_version": "2:4.2.10-0ubuntu4+esm2",
            "binary_name": "rails"
        },
        {
            "binary_version": "2:4.2.10-0ubuntu4+esm2",
            "binary_name": "ruby-actionmailer"
        },
        {
            "binary_version": "2:4.2.10-0ubuntu4+esm2",
            "binary_name": "ruby-actionpack"
        },
        {
            "binary_version": "2:4.2.10-0ubuntu4+esm2",
            "binary_name": "ruby-actionview"
        },
        {
            "binary_version": "2:4.2.10-0ubuntu4+esm2",
            "binary_name": "ruby-activejob"
        },
        {
            "binary_version": "2:4.2.10-0ubuntu4+esm2",
            "binary_name": "ruby-activemodel"
        },
        {
            "binary_version": "2:4.2.10-0ubuntu4+esm2",
            "binary_name": "ruby-activerecord"
        },
        {
            "binary_version": "2:4.2.10-0ubuntu4+esm2",
            "binary_name": "ruby-activesupport"
        },
        {
            "binary_version": "2:4.2.10-0ubuntu4+esm2",
            "binary_name": "ruby-rails"
        },
        {
            "binary_version": "2:4.2.10-0ubuntu4+esm2",
            "binary_name": "ruby-railties"
        }
    ]
}{
    "binaries": [
        {
            "binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
            "binary_name": "rails"
        },
        {
            "binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
            "binary_name": "ruby-actioncable"
        },
        {
            "binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
            "binary_name": "ruby-actionmailer"
        },
        {
            "binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
            "binary_name": "ruby-actionpack"
        },
        {
            "binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
            "binary_name": "ruby-actionview"
        },
        {
            "binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
            "binary_name": "ruby-activejob"
        },
        {
            "binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
            "binary_name": "ruby-activemodel"
        },
        {
            "binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
            "binary_name": "ruby-activerecord"
        },
        {
            "binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
            "binary_name": "ruby-activestorage"
        },
        {
            "binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
            "binary_name": "ruby-activesupport"
        },
        {
            "binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
            "binary_name": "ruby-rails"
        },
        {
            "binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
            "binary_name": "ruby-railties"
        }
    ]
}{
    "binaries": [
        {
            "binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
            "binary_name": "rails"
        },
        {
            "binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
            "binary_name": "ruby-actioncable"
        },
        {
            "binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
            "binary_name": "ruby-actionmailbox"
        },
        {
            "binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
            "binary_name": "ruby-actionmailer"
        },
        {
            "binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
            "binary_name": "ruby-actionpack"
        },
        {
            "binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
            "binary_name": "ruby-actiontext"
        },
        {
            "binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
            "binary_name": "ruby-actionview"
        },
        {
            "binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
            "binary_name": "ruby-activejob"
        },
        {
            "binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
            "binary_name": "ruby-activemodel"
        },
        {
            "binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
            "binary_name": "ruby-activerecord"
        },
        {
            "binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
            "binary_name": "ruby-activestorage"
        },
        {
            "binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
            "binary_name": "ruby-activesupport"
        },
        {
            "binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
            "binary_name": "ruby-rails"
        },
        {
            "binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
            "binary_name": "ruby-railties"
        }
    ]
}