GHSA-fj2w-qmjp-3rjm, CVE-2020-35305
gem/gollum
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Cross site scripting (XSS) in gollum 5.0 to 5.1.2 via the filename parameter to the 'New Page' dialog.
All versions starting from 5.0 before 5.1.2
Upgrade to version 5.1.2 or above.
2022-07-24
source |