Lucene search

K
githubGitHub Advisory DatabaseGHSA-V5JG-558J-Q67C
HistoryOct 24, 2017 - 6:33 p.m.

actionpack Cross-site Scripting vulnerability

2017-10-2418:33:38
CWE-79
GitHub Advisory Database
github.com
22

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.003 Low

EPSS

Percentile

70.1%

Cross-site scripting (XSS) vulnerability in the strip_tags helper in actionpack/lib/action_controller/vendor/html-scanner/html/node.rb in Ruby on Rails before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allows remote attackers to inject arbitrary web script or HTML via a tag with an invalid name.

Affected configurations

Vulners
Node
actionpack_projectactionpackRange<3.0.10ruby
OR
actionpack_projectactionpackRange<2.3.13ruby
CPENameOperatorVersion
actionpacklt3.0.10
actionpacklt2.3.13

References

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.003 Low

EPSS

Percentile

70.1%