PT-2013-5042 · Ruby+1 · I18N Gem+1

Published

2013-12-07

·

Updated

2023-02-13

·

CVE-2013-4492

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions i18n gem versions prior to 0.6.6
Description The issue is related to a cross-site scripting (XSS) vulnerability in the exceptions.rb file of the i18n gem for Ruby. This vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted I18n::MissingTranslationData.new call.
Recommendations For versions prior to 0.6.6, update to version 0.6.6 or later to resolve the issue. As a temporary workaround, consider restricting the use of the I18n::MissingTranslationData.new call to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2013-4492
DSA-2830-1
GHSA-R5HC-9XX5-97RW
MGASA-2014-0017
RHSA-2017:0320
RHSA-2018:0380
SUSE-SU-2014_0458-1

Affected Products

Suse
I18N Gem