UNKNOWN RubyGems
rails Cross-site Scripting vulnerability
GHSA-v9v4-7jp6-8c73 · CVE-2011-2197
Published · Modified
Description
The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2011-2197
- WEB https://github.com/rails/rails/commit/53a2c0baf2b128dd4808eca313256f6f4bb8c4cd
- WEB https://github.com/rails/rails/commit/ed3796434af6069ced6a641293cf88eef3b284da
- WEB https://gist.github.com/NZKoz/b2ceb626fc2bcdfe497f
- PACKAGE https://github.com/rails/rails
- WEB https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activesupport/CVE-2011-2197.yml
- WEB http://groups.google.com/group/rubyonrails-security/msg/663b600d4471e0d4?dmode=source&output=gplain
- WEB http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062514.html
- WEB http://lists.fedoraproject.org/pipermail/package-announce/2011-June/062090.html
- WEB http://openwall.com/lists/oss-security/2011/06/09/2
- WEB http://openwall.com/lists/oss-security/2011/06/13/9
- WEB http://weblog.rubyonrails.org/2011/6/8/potential-xss-vulnerability-in-ruby-on-rails-applications
Ready to move
Start Securing
Free, no credit card | First findings in minutes