USN-4089-1: Rack vulnerability
7 August 2019
Rack could allow cross-site scripting (XSS) attacks.
Releases
Packages
- ruby-rack - modular Ruby webserver interface
Details
It was discovered that Rack incorrectly handled carefully crafted requests. A
remote attacker could use this issue to execute a cross-site scripting (XSS)
attack.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.04
Ubuntu 16.04
In general, a standard system update will make all the necessary changes.