Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-23913

Опубликовано: 09 янв. 2025
Источник: debian
EPSS Низкий

Описание

There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
railsfixed2:6.1.7.3+dfsg-1package

Примечания

  • https://github.com/rails/rails/commit/5037a13614d71727af8a175063bcf6ba1a74bdbd (v6.1.7.3)

  • https://discuss.rubyonrails.org/t/cve-2023-23913-dom-based-cross-site-scripting-in-rails-ujs-for-contenteditable-html-elements/82468

EPSS

Процентиль: 20%
0.00065
Низкий

Связанные уязвимости

CVSS3: 6.3
ubuntu
около 1 года назад

There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.

CVSS3: 7.5
redhat
почти 3 года назад

There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.

CVSS3: 6.3
nvd
около 1 года назад

There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.

suse-cvrf
больше 2 лет назад

Security update for rubygem-actionview-5_1

CVSS3: 6.3
github
больше 2 лет назад

rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements

EPSS

Процентиль: 20%
0.00065
Низкий