Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vxvp-4xwc-jpp6

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

activesupport Cross-site Scripting vulnerability

Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding.

Пакеты

Наименование

activesupport

rubygems
Затронутые версииВерсия исправления

>= 4.1.0, < 4.1.11

4.1.11

Наименование

activesupport

rubygems
Затронутые версииВерсия исправления

>= 4.2.0, < 4.2.2

4.2.2

EPSS

Процентиль: 44%
0.00212
Низкий

Дефекты

CWE-79

Связанные уязвимости

ubuntu
больше 10 лет назад

Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding.

redhat
больше 10 лет назад

Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding.

nvd
больше 10 лет назад

Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding.

debian
больше 10 лет назад

Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active ...

EPSS

Процентиль: 44%
0.00212
Низкий

Дефекты

CWE-79