Описание
Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML via the (1) format, (2) negative_format, or (3) units parameter to the (a) number_to_currency, (b) number_to_percentage, or (c) number_to_human helper.
Отчет
Red Hat OpenShift Enterprise 1.2 is now in Production 1 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat OpenShift Enterprise Life Cycle: https://access.redhat.com/site/support/policy/updates/openshift.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Enterprise 1 | ruby193-rubygem-actionpack | Will not fix | ||
| Red Hat OpenStack Platform 3 | ruby193-rubygem-actionpack | Affected | ||
| Red Hat OpenStack Platform 4 | ruby193-rubygem-actionpack | Affected | ||
| Red Hat Satellite 6 | ruby193-rubygem-actionpack | Affected | ||
| Red Hat Software Collections | ror40-rubygem-actionpack | Affected | ||
| Red Hat Subscription Asset Manager | ruby193-rubygem-actionpack | Will not fix | ||
| CloudForms Management Engine 5.x | cfme | Fixed | RHSA-2014:0215 | 11.03.2014 |
| CloudForms Management Engine 5.x | ruby193-ruby | Fixed | RHSA-2014:0215 | 11.03.2014 |
| CloudForms Management Engine 5.x | ruby193-rubygem-actionpack | Fixed | RHSA-2014:0215 | 11.03.2014 |
| CloudForms Management Engine 5.x | ruby193-rubygem-amq-protocol | Fixed | RHSA-2014:0215 | 11.03.2014 |
Показывать по
Дополнительная информация
Статус:
4.3 Medium
CVSS2
Связанные уязвимости
Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML via the (1) format, (2) negative_format, or (3) units parameter to the (a) number_to_currency, (b) number_to_percentage, or (c) number_to_human helper.
Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML via the (1) format, (2) negative_format, or (3) units parameter to the (a) number_to_currency, (b) number_to_percentage, or (c) number_to_human helper.
Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/ ...
4.3 Medium
CVSS2