Haml 2.2.24 for Ruby

CPE Details

Haml 2.2.24 for Ruby
2.2.24
2019-10-16
12h24 +00:00
2019-10-16
12h24 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:haml:haml:2.2.24:*:*:*:*:ruby:*:*

Informations

Vendor

haml

Product

haml

Version

2.2.24

Target Software

ruby

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2017-1002201 2019-10-15 15h35 +00:00 In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < > " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate the input to introduce additional attributes, potentially executing code.
6.1
Medium