Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9p3v-wf2w-v29c

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

Moderate severity vulnerability that affects rails

Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII characters, related to HTML::Tokenizer and actionpack/lib/action_controller/vendor/html-scanner/html/node.rb.

Пакеты

Наименование

rails

rubygems
Затронутые версииВерсия исправления

< 2.2.2

2.2.2

Наименование

rails

rubygems
Затронутые версииВерсия исправления

>= 2.3.0, < 2.3.5

2.3.5

EPSS

Процентиль: 81%
0.01632
Низкий

Дефекты

CWE-79

Связанные уязвимости

ubuntu
около 16 лет назад

Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII characters, related to HTML::Tokenizer and actionpack/lib/action_controller/vendor/html-scanner/html/node.rb.

redhat
около 16 лет назад

Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII characters, related to HTML::Tokenizer and actionpack/lib/action_controller/vendor/html-scanner/html/node.rb.

nvd
около 16 лет назад

Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII characters, related to HTML::Tokenizer and actionpack/lib/action_controller/vendor/html-scanner/html/node.rb.

debian
около 16 лет назад

Cross-site scripting (XSS) vulnerability in the strip_tags function in ...

EPSS

Процентиль: 81%
0.01632
Низкий

Дефекты

CWE-79