VDB

CVE-2024-27285

CVE-2024-27285 PUBLISHED CVSS 5.400000095367432 MEDIUM

YARD's default template vulnerable to Cross-site Scripting in generated frames.html

EPSS 1.06% · 61.8th percentile

Risk Scores

CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS Score
1.06%
61.8th percentile

Affected Products

VendorProductVersions
yardocyard0, 0
lsegalyard< 0.9.36, < 0.9.36
fedoraprojectfedora38, 38
debiandebian_linux10.0, 10.0
RubyGemsyard0, 0
yardocyard0.9.36, 0.9.36

Timeline

  • Jan 20, 1970 Fix PR Merged
  • Jan 21, 1970 Security Advisory
  • Feb 28, 2024 CVE Published
  • Feb 28, 2024 PoC Published
  • Feb 28, 2024 PoC Published
  • Feb 29, 2024 EPSS Score
  • Mar 27, 2024 EPSS Score
  • May 19, 2024 EPSS Score
  • Jun 15, 2024 EPSS Score
  • Aug 8, 2024 EPSS Score
  • Sep 4, 2024 EPSS Score
  • Sep 30, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›