Update actionpack to >= 6.0.3.4 to address CVE-2020-8264
A customer scan brought CVE-2020-8264 to our attention:
There is a possible XSS vulnerability in Action Pack while the application
server is in development mode. This vulnerability is in the Actionable
Exceptions middleware. This vulnerability has been assigned the CVE
identifier CVE-2020-8264.
Versions Affected: >= 6.0.0
Not affected: < 6.0.0
Fixed Versions: 6.0.3.4
Impact
------
When an application is running in development mode, and attacker can send or
embed (in another page) a specially crafted URL which can allow the attacker
to execute JavaScript in the context of the local application.
In order to address this, we will need to bump actionpack to >= 6.0.3.4
.