Описание
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback string by the i18n gem.
It was discovered that the internationalization component of Ruby on Rails could, under certain circumstances, return a fallback HTML string that contained user input. A remote attacker could possibly use this flaw to perform a reflective cross-site scripting (XSS) attack by providing a specially crafted input to an application using the aforementioned component.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| CloudForms Management Engine 5 | ruby193-rubygem-actionpack | Will not fix | ||
| OpenShift Enterprise 1 | ruby193-rubygem-actionpack | Will not fix | ||
| Red Hat OpenStack Platform 4 | ruby193-rubygem-actionpack | Not affected | ||
| Red Hat Satellite 6 | ruby193-rubygem-actionpack | Affected | ||
| Red Hat Software Collections | ror40-rubygem-actionpack | Not affected | ||
| Red Hat Subscription Asset Manager | rubygem-actionpack | Affected | ||
| OpenStack 3 for RHEL 6 | ruby193-rubygem-actionpack | Fixed | RHSA-2014:0008 | 06.01.2014 |
| Red Hat Software Collections for RHEL-6 | ruby193-rubygem-actionpack | Fixed | RHSA-2013:1794 | 05.12.2013 |
| Red Hat Subscription Asset Manager 1.4 | katello | Fixed | RHSA-2014:1863 | 17.11.2014 |
| Red Hat Subscription Asset Manager 1.4 | ruby193-rubygem-actionmailer | Fixed | RHSA-2014:1863 | 17.11.2014 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback string by the i18n gem.
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback string by the i18n gem.
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view ...
EPSS
4.3 Medium
CVSS2