Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-5267

Опубликовано: 19 мар. 2020
Источник: debian
EPSS Низкий

Описание

In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript literal escape helpers. Views that use the `j` or `escape_javascript` methods may be susceptible to XSS attacks. The issue is fixed in versions 6.0.2.2 and 5.2.4.2.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
railsfixed2:5.2.4.1+dfsg-2package
railsfixed2:5.2.2.1+dfsg-1+deb10u1busterpackage
railsfixed2:4.2.7.1-1+deb9u2stretchpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2020/03/19/1

  • https://github.com/rails/rails/commit/033a738817abd6e446e1b320cb7d1a5c15224e9a (master)

EPSS

Процентиль: 75%
0.00887
Низкий

Связанные уязвимости

CVSS3: 4
ubuntu
почти 6 лет назад

In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript literal escape helpers. Views that use the `j` or `escape_javascript` methods may be susceptible to XSS attacks. The issue is fixed in versions 6.0.2.2 and 5.2.4.2.

CVSS3: 4.8
redhat
почти 6 лет назад

In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript literal escape helpers. Views that use the `j` or `escape_javascript` methods may be susceptible to XSS attacks. The issue is fixed in versions 6.0.2.2 and 5.2.4.2.

CVSS3: 4
nvd
почти 6 лет назад

In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript literal escape helpers. Views that use the `j` or `escape_javascript` methods may be susceptible to XSS attacks. The issue is fixed in versions 6.0.2.2 and 5.2.4.2.

suse-cvrf
больше 5 лет назад

Security update for rubygem-actionview-5_1

suse-cvrf
почти 6 лет назад

Security update for rubygem-actionview-5_1

EPSS

Процентиль: 75%
0.00887
Низкий