Lucene search

K
rubygemsRubySecRUBY:ACTIONPACK-2013-4491-100528
HistoryDec 02, 2013 - 8:00 p.m.

Reflective XSS Vulnerability in Ruby on Rails

2013-12-0220:00:00
RubySec
rubysec.com
13

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.003 Low

EPSS

Percentile

65.9%

There is a vulnerability in the internationalization component of Ruby on
Rails. Under certain common configurations an attacker can provide specially
crafted input which will execute a reflective XSS attack.

The root cause of this issue is a vulnerability in the i18n gem which has
been assigned the identifier CVE-2013-4492.

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.003 Low

EPSS

Percentile

65.9%