Reflected cross-site scripting (XSS) In actionview
Description
actionview Cross-site Scripting vulnerability Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or HTML via text declared as "HTML safe" and used as attribute values in tag handlers.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rubygems | 3.2.22.3, 4.2.7.1, 5.0.0.1 | ||
rubygems | 3.2.22.3 | ||
debian 12 | 2:4.2.7.1-1 | ||
debian 13 | 2:4.2.7.1-1 | ||
debian 14 | 2:4.2.7.1-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12.