GHSA-9p3v-wf2w-v29c

Source
https://github.com/advisories/GHSA-9p3v-wf2w-v29c
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-9p3v-wf2w-v29c/GHSA-9p3v-wf2w-v29c.json
Aliases
  • CVE-2009-4214
Published
2017-10-24T18:33:38Z
Modified
2024-02-16T08:19:40.056176Z
Details

Cross-site scripting (XSS) vulnerability in the striptags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII characters, related to HTML::Tokenizer and actionpack/lib/actioncontroller/vendor/html-scanner/html/node.rb.

References

Affected packages

RubyGems / rails

Package

Name
rails

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
2.2.2

Affected versions

0.*

0.8.0
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
0.9.4.1
0.9.5
0.10.0
0.10.1
0.11.0
0.11.1
0.12.0
0.12.1
0.13.0
0.13.1
0.14.1
0.14.2
0.14.3
0.14.4

1.*

1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6

2.*

2.0.0
2.0.1
2.0.2
2.0.4
2.0.5
2.1.0
2.1.1
2.1.2

RubyGems / rails

Package

Name
rails

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.3.0
Fixed
2.3.5

Affected versions

2.*

2.3.2
2.3.3
2.3.4