Описание
Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter.
It was found that the number_to_currency Action View helper did not properly escape the unit parameter. An attacker could use this flaw to perform a cross-site scripting (XSS) attack on an application that uses data submitted by a user in the unit parameter.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| CloudForms Management Engine 5 | ruby193-rubygem-actionpack | Affected | ||
| OpenShift Enterprise 1 | ruby193-rubygem-actionpack | Will not fix | ||
| Red Hat OpenStack Platform 4 | ruby193-rubygem-actionpack | Not affected | ||
| Red Hat Satellite 6 | ruby193-rubygem-actionpack | Affected | ||
| Red Hat Software Collections | ror40-rubygem-actionpack | Not affected | ||
| Red Hat Subscription Asset Manager | rubygem-actionpack | Affected | ||
| OpenStack 3 for RHEL 6 | ruby193-rubygem-actionpack | Fixed | RHSA-2014:0008 | 06.01.2014 |
| Red Hat Software Collections for RHEL-6 | ruby193-rubygem-actionpack | Fixed | RHSA-2013:1794 | 05.12.2013 |
| Red Hat Subscription Asset Manager 1.4 | katello | Fixed | RHSA-2014:1863 | 17.11.2014 |
| Red Hat Subscription Asset Manager 1.4 | ruby193-rubygem-actionmailer | Fixed | RHSA-2014:1863 | 17.11.2014 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter.
Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter.
Cross-site scripting (XSS) vulnerability in the number_to_currency hel ...
EPSS
4.3 Medium
CVSS2