Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-6316

Опубликовано: 11 авг. 2016
Источник: redhat
CVSS3: 6.1
CVSS2: 4.3

Описание

Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or HTML via text declared as "HTML safe" and used as attribute values in tag handlers.

It was discovered that Action View tag helpers did not escape quotes when using strings declared as HTML safe as attribute values. A remote attacker could use this flaw to conduct a cross-site scripting (XSS) attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Subscription Asset Managerruby193-rubygem-actionpackAffected
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-ror41-rubygem-actionviewFixedRHSA-2016:185613.09.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6ror40-rubygem-actionpackFixedRHSA-2016:185713.09.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6ruby193-rubygem-actionpackFixedRHSA-2016:185813.09.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSrh-ror41-rubygem-actionviewFixedRHSA-2016:185613.09.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSror40-rubygem-actionpackFixedRHSA-2016:185713.09.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSruby193-rubygem-actionpackFixedRHSA-2016:185813.09.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSrh-ror41-rubygem-actionviewFixedRHSA-2016:185613.09.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSror40-rubygem-actionpackFixedRHSA-2016:185713.09.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSruby193-rubygem-actionpackFixedRHSA-2016:185813.09.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1365008rubygem-actionview: cross-site scripting flaw in Action View

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 9 лет назад

Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or HTML via text declared as "HTML safe" and used as attribute values in tag handlers.

CVSS3: 6.1
nvd
больше 9 лет назад

Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or HTML via text declared as "HTML safe" and used as attribute values in tag handlers.

CVSS3: 6.1
debian
больше 9 лет назад

Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rai ...

CVSS3: 6.1
github
больше 8 лет назад

actionview Cross-site Scripting vulnerability

6.1 Medium

CVSS3

4.3 Medium

CVSS2