Cross-site scripting (XSS) vulnerability in the will_paginate gem before 3.0.5 for Ruby allows remote attackers to inject arbitrary web script or HTML via vectors involving generated pagination links.
https://github.com/mislav/will_paginate/releases/tag/v3.0.5
https://access.redhat.com/errata/RHSA-2018:0336