MEDIUM
GHSA-v9v4-7jp6-8c73
rails Cross-site Scripting vulnerability
상세
The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
참고
- https://nvd.nist.gov/vuln/detail/CVE-2011-2197 [ADVISORY]
- https://github.com/rails/rails/commit/53a2c0baf2b128dd4808eca313256f6f4bb8c4cd [WEB]
- https://github.com/rails/rails/commit/ed3796434af6069ced6a641293cf88eef3b284da [WEB]
- https://gist.github.com/NZKoz/b2ceb626fc2bcdfe497f [WEB]
- https://github.com/rails/rails [PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activesupport/CVE-2011-2197.yml [WEB]
- http://groups.google.com/group/rubyonrails-security/msg/663b600d4471e0d4?dmode=source&output=gplain [WEB]
- http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062514.html [WEB]
- http://lists.fedoraproject.org/pipermail/package-announce/2011-June/062090.html [WEB]
- http://openwall.com/lists/oss-security/2011/06/09/2 [WEB]
- http://openwall.com/lists/oss-security/2011/06/13/9 [WEB]
- http://weblog.rubyonrails.org/2011/6/8/potential-xss-vulnerability-in-ruby-on-rails-applications [WEB]