PT-2013-2191 · Ruby+2 · Rdoc+3

Evgeny Ermakov

·

Published

2013-03-01

·

Updated

2025-09-29

·

CVE-2013-0256

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions RDoc versions 2.3.0 through 3.12 RDoc versions 4.x before 4.0.0.preview2.1
Description The issue allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, due to improper document generation by darkfish.js in RDoc.
Recommendations For RDoc versions 2.3.0 through 3.12, update to a version outside of this range to resolve the issue. For RDoc versions 4.x before 4.0.0.preview2.1, update to version 4.0.0.preview2.1 or later to resolve the issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2016-2061
CVE-2013-0256
DLA-235-1
GHSA-V2R9-C84J-V7XM
RHSA-2013:0701
RHSA-2013:0728
SUSE-SU-2013_0384-1

Affected Products

Alt Linux
Rdoc
Ruby
Suse