VDB
Sign up
MEDIUM4.8

GHSA-65cv-r6x7-79hv

Cross site scripting vulnerability in ActionView

Quick fix

GHSA-65cv-r6x7-79hv — actionview: upgrade to the fixed version with the command below.

bundle update actionview

Details

There is a possible cross site scripting (XSS) vulnerability in ActionView's JavaScript literal escape helpers. Views that use the `j` or `escape_javascript` methods may be susceptible to XSS attacks.

### Impact

There is a possible XSS vulnerability in the `j` and `escape_javascript` methods in ActionView. These methods are used for escaping JavaScript string literals. Impacted code will look something like this:

```erb <script>let a = `<%= j unknown_input %>`</script> ```

or

```erb <script>let a = `<%= escape_javascript unknown_input %>`</script> ```

### Releases

The 6.0.2.2 and 5.2.4.2 releases are available at the normal locations.

### Workarounds

For those that can't upgrade, the following monkey patch may be used:

```ruby ActionView::Helpers::JavaScriptHelper::JS_ESCAPE_MAP.merge!( { "`" => "\\`", "$" => "\\$" } )

module ActionView::Helpers::JavaScriptHelper alias :old_ej :escape_javascript alias :old_j :j

def escape_javascript(javascript) javascript = javascript.to_s if javascript.empty? result = "" else result = javascript.gsub(/(\\|<\/|\r\n|\342\200\250|\342\200\251|[\n\r"']|[`]|[$])/u, JS_ESCAPE_MAP) end javascript.html_safe? ? result.html_safe : result end

alias :j :escape_javascript end ```

### Patches

To aid users who aren't able to upgrade immediately we have provided patches for the two supported release series. They are in git-am format and consist of a single changeset.

* [5-2-js-helper-xss.patch](https://gist.github.com/tenderlove/c042ff49f0347c37e99183a6502accc6#file-5-2-js-helper-xss-patch) - Patch for 5.2 series * [6-0-js-helper-xss.patch](https://gist.github.com/tenderlove/c042ff49f0347c37e99183a6502accc6#file-6-0-js-helper-xss-patch) - Patch for 6.0 series

Please note that only the 5.2 and 6.0 series are supported at present. Users of earlier unsupported releases are advised to upgrade as soon as possible as we cannot guarantee the continued availability of security fixes for unsupported releases.

### Credits

Thanks to Jesse Campos from Chef Secure

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/actionview
Introduced in: 0Fixed in: 5.2.4.2
Fixbundle update actionview
RubyGems/actionview
Introduced in: 6.0.0Fixed in: 6.0.2.2
Fixbundle update actionview

References