Описание
A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker to inject content if able to control input into specific attributes.
Ссылки
- ExploitPatchVendor Advisory
- Mailing ListThird Party Advisory
- ExploitPatchVendor Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.2.7.1 (исключая)Версия от 6.0.0 (включая) до 6.0.4.8 (исключая)Версия от 6.1.0 (включая) до 6.1.5.1 (исключая)Версия от 7.0.0 (включая) до 7.0.2.4 (исключая)
Одно из
cpe:2.3:a:rubyonrails:actionpack:*:*:*:*:*:ruby:*:*
cpe:2.3:a:rubyonrails:actionpack:*:*:*:*:*:ruby:*:*
cpe:2.3:a:rubyonrails:actionpack:*:*:*:*:*:ruby:*:*
cpe:2.3:a:rubyonrails:actionpack:*:*:*:*:*:ruby:*:*
Конфигурация 2
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
EPSS
Процентиль: 78%
0.01155
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
CWE-79
Связанные уязвимости
CVSS3: 6.1
ubuntu
больше 3 лет назад
A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker to inject content if able to control input into specific attributes.
CVSS3: 7.5
redhat
почти 4 года назад
A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker to inject content if able to control input into specific attributes.
CVSS3: 6.1
debian
больше 3 лет назад
A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 wh ...
EPSS
Процентиль: 78%
0.01155
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
CWE-79