PT-2013-5042 · Ruby+1 · I18N Gem+1

CVE-2013-4492

·

Publicado

2013-12-07

·

Atualizado

2023-02-13

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions i18n gem versions prior to 0.6.6
Description The issue is related to a cross-site scripting (XSS) vulnerability in the exceptions.rb file of the i18n gem for Ruby. This vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted I18n::MissingTranslationData.new call.
Recommendations For versions prior to 0.6.6, update to version 0.6.6 or later to resolve the issue. As a temporary workaround, consider restricting the use of the I18n::MissingTranslationData.new call to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-4492
DSA-2830-1
GHSA-R5HC-9XX5-97RW
MGASA-2014-0017
RHSA-2017:0320
RHSA-2018:0380
SUSE-SU-2014_0458-1

Produtos afetados

Suse
I18N Gem