Cross-site scripting (XSS) vulnerability in the will_paginate gem before 3.0.5 for Ruby allows remote attackers to inject arbitrary web script or HTML via vectors involving generated pagination links.
https://github.com/advisories/GHSA-8r6h-7x9g-xmw9
https://github.com/mislav/will_paginate/releases/tag/v3.0.5
https://access.redhat.com/errata/RHSA-2018:0336