PT-2011-3677 · Ruby · Ruby On Rails

Josh Bressers

·

Publicado

2011-06-30

·

Atualizado

2019-08-08

·

CVE-2011-2197

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Ruby on Rails versions 2.x through 2.3.11 Ruby on Rails versions 3.0.x through 3.0.7 Ruby on Rails versions 3.1.x through 3.1.0.rc1
Description The issue is related to the cross-site scripting (XSS) prevention feature, which does not properly handle mutation of safe buffers. This makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method.
Recommendations For Ruby on Rails versions 2.x through 2.3.11, update to version 2.3.12 or later. For Ruby on Rails versions 3.0.x through 3.0.7, update to version 3.0.8 or later. For Ruby on Rails versions 3.1.x through 3.1.0.rc1, update to version 3.1.0.rc2 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-2197
GHSA-V9V4-7JP6-8C73

Produtos afetados

Ruby On Rails