[DRE-maint] Bug#790395: ruby-jquery-rails: CVE-2015-1840

Salvatore Bonaccorso carnil at debian.org
Sun Jun 28 21:01:45 UTC 2015


Source: ruby-jquery-rails
Version: 3.1.2-6
Severity: important
Tags: security upstream fixed-upstream

Hi,

the following vulnerability was published for ruby-jquery-rails,
filling for reference as well in the BTS.

CVE-2015-1840[0]:
CSRF vulnerability in jquery-rails

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2015-1840
[1] https://bugzilla.novell.com/show_bug.cgi?id=934795
[2] https://marc.info/?l=oss-security&m=143447798114356&w=2

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



More information about the Pkg-ruby-extras-maintainers mailing list