Executive brief
### Impact The debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject arbitrary HTML and JavaScript into the page, leading to XSS. This affects applications with detailed exception pages enabled (`config.consider_all_requests_local = true`), which is the default in development.
### Releases The fixed releases are available at the normal locations.
### Credit This issue was responsibly reported by Hackerone researcher [fbettag](https://hackerone.com/fbettag).
Affected products
- RubyGems actionpack