VDB
KO
MEDIUM

GHSA-7g65-ghrg-hpf5

actionpack Cross-site Scripting vulnerability

Details

Cross-site scripting (XSS) vulnerability in `actionpack/lib/action_view/helpers/sanitize_helper.rb` in the `strip_tags` helper in Ruby on Rails before 2.3.16, 3.0.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via malformed HTML markup.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems / actionpack
Introduced in: 3.0.0.beta Fixed in: 3.0.17
Fix bundle update actionpack
RubyGems / actionpack
Introduced in: 3.1.0 Fixed in: 3.1.8
Fix bundle update actionpack
RubyGems / actionpack
Introduced in: 3.2.0 Fixed in: 3.2.8
Fix bundle update actionpack
RubyGems / actionpack
Introduced in: 0 Fixed in: 2.3.16
Fix bundle update actionpack

References