A cross-site scripting vulnerability flaw was found in the auto_link function in Rails before version 3.0.6. References: https://www.openwall.com/lists/oss-security/2011/04/06/13 https://github.com/rails/rails/blob/38df020c95beca7e12f0188cb7e18f3c37789e20/actionpack/CHANGELOG
Upstream fix: https://github.com/rails/rails/commit/61ee3449674c591747db95f9b3472c5c3bd9e84d
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2011-1497