Описание
Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem before 0.6.6 for Ruby allows remote attackers to inject arbitrary web script or HTML via a crafted I18n::MissingTranslationData.new call.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Enterprise 1 | ruby193-rubygem-i18n | Will not fix | ||
| Red Hat OpenShift Enterprise 2 | ruby193-rubygem-i18n | Will not fix | ||
| Red Hat OpenStack Platform 3 | ruby193-rubygem-i18n | Will not fix | ||
| Red Hat OpenStack Platform 4 | ruby193-rubygem-i18n | Will not fix | ||
| Red Hat Software Collections | ror40-rubygem-i18n | Will not fix | ||
| Red Hat Software Collections | ruby193-rubygem-i18n | Will not fix | ||
| Red Hat Subscription Asset Manager | ruby193-rubygem-i18n | Will not fix | ||
| Red Hat Subscription Asset Manager | rubygem-i18n | Will not fix | ||
| CloudForms Management Engine 5.4 | cfme | Fixed | RHBA-2015:1100 | 16.06.2015 |
| CloudForms Management Engine 5.4 | cfme-gemset | Fixed | RHBA-2015:1100 | 16.06.2015 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem before 0.6.6 for Ruby allows remote attackers to inject arbitrary web script or HTML via a crafted I18n::MissingTranslationData.new call.
Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem before 0.6.6 for Ruby allows remote attackers to inject arbitrary web script or HTML via a crafted I18n::MissingTranslationData.new call.
Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n ...
EPSS
4.3 Medium
CVSS2