
A vulnerability was discovered in the content_security_policy helper in Action Pack of Ruby on Rails. Carefully crafted inputs were able to inject new directives into the Content-Security-Policy (CSP) header, potentially leading to a bypass of the CSP and its protection against cross-site scripting (XSS) and other attacks. The vulnerability affected versions 5.2.0 through 7.0.8.6, 7.1.0 through 7.1.5.0, 7.2.0 through 7.2.2.0, and 8.0.0. The issue was addressed in versions 7.0.8.7, 7.1.5.1, 7.2.2.1, and...
SOCIAL SHARE CARD GENERATOR