Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-1098

Опубликовано: 01 мар. 2012
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving a SafeBuffer object that is manipulated through certain methods.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat CloudForms Tools 1rubygem-activesupportAffected
Red Hat Subscription Asset Managerrubygem-activesupportAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=799275rubygem-activesupport: XSS in SafeBuffer#[] (unescaped safe buffers can be marked as safe)

EPSS

Процентиль: 59%
0.00377
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 14 лет назад

Cross-site scripting (XSS) vulnerability in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving a SafeBuffer object that is manipulated through certain methods.

nvd
почти 14 лет назад

Cross-site scripting (XSS) vulnerability in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving a SafeBuffer object that is manipulated through certain methods.

debian
почти 14 лет назад

Cross-site scripting (XSS) vulnerability in Ruby on Rails 3.0.x before ...

github
больше 8 лет назад

activesupport Cross-site Scripting vulnerability

EPSS

Процентиль: 59%
0.00377
Низкий

4.3 Medium

CVSS2