Ruby · Ruby On Rails · CVE-2012-3464
**Name of the Vulnerable Software and Affected Versions**
Ruby on Rails versions prior to 2.3.16
Ruby on Rails versions 3.0.x through 3.0.16
Ruby on Rails versions 3.1.x through 3.1.7
Ruby on Rails versions 3.2.x through 3.2.7
**Description**
A cross-site scripting (XSS) issue might allow remote attackers to inject arbitrary web script or HTML via vectors involving a ' (quote) character. This is due to a vulnerability in the activesupport/lib/active support/core ext/string/output safety.rb file.
**Recommendations**
For Ruby on Rails versions prior to 2.3.16, update to version 2.3.16 or later.
For Ruby on Rails versions 3.0.x through 3.0.16, update to version 3.0.17 or later.
For Ruby on Rails versions 3.1.x through 3.1.7, update to version 3.1.8 or later.
For Ruby on Rails versions 3.2.x through 3.2.7, update to version 3.2.8 or later.