PT-2011-3677 · Ruby · Ruby On Rails
Josh Bressers
·
Published
2011-06-30
·
Updated
2019-08-08
·
CVE-2011-2197
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Ruby on Rails versions 2.x through 2.3.11
Ruby on Rails versions 3.0.x through 3.0.7
Ruby on Rails versions 3.1.x through 3.1.0.rc1
Description
The issue is related to the cross-site scripting (XSS) prevention feature, which does not properly handle mutation of safe buffers. This makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method.
Recommendations
For Ruby on Rails versions 2.x through 2.3.11, update to version 2.3.12 or later.
For Ruby on Rails versions 3.0.x through 3.0.7, update to version 3.0.8 or later.
For Ruby on Rails versions 3.1.x through 3.1.0.rc1, update to version 3.1.0.rc2 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ruby On Rails