Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-28120

Опубликовано: 15 мар. 2023
Источник: redhat
CVSS3: 6.1

Описание

There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.

A Cross-Site-Scripting vulnerability was found in rubygem ActiveSupport. If the new bytesplice method is called on a SafeBuffer with untrusted user input, malicious code could be executed.

Меры по смягчению последствий

Avoid calling bytesplice on a SafeBuffer (html_safe) string with untrusted user input.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp-backend-containerAffected
Red Hat 3scale API Management Platform 23scale-amp-zync-containerWill not fix
Red Hat 3scale API Management Platform 23scale-toolbox-containerWill not fix
Red Hat OpenShift Container Platform 3.11rubygem-activesupportOut of support scope
Red Hat Satellite 6candlepinNot affected
Red Hat Satellite 6rubygem-activesupportNot affected
Red Hat Satellite 6rubygem-deep_cloneableNot affected
RHOL-5.6-RHEL-8openshift-logging/fluentd-rhel8FixedRHSA-2023:195326.04.2023
RHOL-5.7-RHEL-8openshift-logging/fluentd-rhel8FixedRHSA-2023:349512.06.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2179637rubygem-activesupport: Possible XSS in SafeBuffer#bytesplice

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 года назад

There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.

CVSS3: 5.3
nvd
около 1 года назад

There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.

CVSS3: 5.3
debian
около 1 года назад

There is a vulnerability in ActiveSupport if the new bytesplice method ...

CVSS3: 5.3
github
почти 3 года назад

Possible XSS Security Vulnerability in SafeBuffer#bytesplice

suse-cvrf
больше 2 лет назад

Security update for rmt-server

6.1 Medium

CVSS3