Описание
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_tag_helper.rb in Ruby on Rails 3.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the prompt field to the select_tag helper.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat CloudForms Tools 1 | rubygem-actionpack | Affected | ||
| CloudForms for RHEL 6 | converge-ui-devel | Fixed | RHSA-2012:1542 | 04.12.2012 |
| CloudForms for RHEL 6 | puppet | Fixed | RHSA-2012:1542 | 04.12.2012 |
| CloudForms for RHEL 6 | rubygem-actionpack | Fixed | RHSA-2012:1542 | 04.12.2012 |
| CloudForms for RHEL 6 | rubygem-activerecord | Fixed | RHSA-2012:1542 | 04.12.2012 |
| CloudForms for RHEL 6 | rubygem-activesupport | Fixed | RHSA-2012:1542 | 04.12.2012 |
| CloudForms for RHEL 6 | rubygem-chunky_png | Fixed | RHSA-2012:1542 | 04.12.2012 |
| CloudForms for RHEL 6 | rubygem-compass | Fixed | RHSA-2012:1542 | 04.12.2012 |
| CloudForms for RHEL 6 | rubygem-compass-960-plugin | Fixed | RHSA-2012:1542 | 04.12.2012 |
| CloudForms for RHEL 6 | rubygem-delayed_job | Fixed | RHSA-2012:1542 | 04.12.2012 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_tag_helper.rb in Ruby on Rails 3.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the prompt field to the select_tag helper.
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_tag_helper.rb in Ruby on Rails 3.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the prompt field to the select_tag helper.
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view ...
EPSS
4.3 Medium
CVSS2