æ¨æ¥ãRuby on Railsã®éè¦ãªã»ãã¥ãªãã£ã¢ãããã¼ãã§ãããRails 4.0.2ã¨3.2.16ããªãªã¼ã¹ããã¾ããã ãã®ãªãªã¼ã¹ã«ã¯ã5件(3.2.16ã«ã¯4件)ã®ã»ãã¥ãªãã£FIXãå«ã¾ãã¦ãã¾ãã éè¦åº¦ã®é«ããã®ããããããæ©æ¥ãªã¢ãããã¼ãããã¾ãããã CVE-2013-6416 simple_formatãã«ãã¼ã®XSSèå¼±æ§ã«é¢ããä¿®æ£ã§ãã â»4.0.2ã®ã¿ã3.2ç³»ã§ã¯å ããçºçããªãããã3.2.16ã«ã¯å«ã¾ãã¾ããã simple_formatã¯html_optionsã¨ãã¦Hashã渡ãã¾ãããããã©ã«ãã§ããã®classæå®ãHTMLã¨ã¹ã±ã¼ãããã¦ãã¾ããã§ããã classæå®ãã¦ã¼ã¶å ¥åã«ããå ´åã容æã«XSSãæç«ãã¦ãã¾ãã¾ãã simple_format "hello\nworld", class: '"><script>alert(1

{{#tags}}- {{label}}
{{/tags}}