Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v9v4-7jp6-8c73

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

rails Cross-site Scripting vulnerability

The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.

Пакеты

Наименование

actionpack

rubygems
Затронутые версииВерсия исправления

>= 2.0.0, < 2.3.11

2.3.12

Наименование

actionpack

rubygems
Затронутые версииВерсия исправления

>= 3.0.0, < 3.0.7

3.0.8

Наименование

activesupport

rubygems
Затронутые версииВерсия исправления

>= 2.0.0, < 2.3.11

2.3.12

Наименование

activesupport

rubygems
Затронутые версииВерсия исправления

>= 3.0.0, < 3.0.7

3.0.8

EPSS

Процентиль: 63%
0.00442
Низкий

Дефекты

CWE-79

Связанные уязвимости

ubuntu
больше 14 лет назад

The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.

nvd
больше 14 лет назад

The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.

debian
больше 14 лет назад

The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x ...

EPSS

Процентиль: 63%
0.00442
Низкий

Дефекты

CWE-79