Haml 1.5.0 for Ruby

CPE Details

Haml 1.5.0 for Ruby
1.5.0
2019-10-16
12h24 +00:00
2019-10-16
12h24 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:haml:haml:1.5.0:*:*:*:*:ruby:*:*

Informations

Vendor

haml

Product

haml

Version

1.5.0

Target Software

ruby

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2017-1002201 2019-10-15 15h35 +00:00 In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < > " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate the input to introduce additional attributes, potentially executing code.
6.1
Medium