Lucene search

K
gitlabHttps://gitlab.com/gitlab-org/security-products/gemnasium-dbGITLAB-5AF31415698B2FAAF1E24F701ED1CC55
HistoryDec 06, 2013 - 12:00 a.m.

Reflective XSS Vulnerability

2013-12-0600:00:00
https://gitlab.com/gitlab-org/security-products/gemnasium-db
gitlab.com
15

EPSS

0.005

Percentile

76.1%

There is a vulnerability in the internationalisation component of Ruby on Rails. When the i18n gem is unable to provide a translation for a given string, it creates a fallback HTML string. Under certain common configurations this string can contain user input which would allow an attacker to execute a reflective XSS attack.